Net Flow
Net Flow
l Configure NetFlow Output on the event source. See the associated documentation for
each individual event source for help in configuring the event source to send NetFlow
data.
About NetFlow
NetFlow was created for the purpose of generating flow information, (source IP, source
port, destination IP, destination port). That flow information is then used for optimizing
network flow through the routers and switches. Additionally, the flow information
generated is useful for reporting and providing useful insights from a RSA NetWitness
Platform perspective.
NetFlow reports the flow information by way of flow records. These records contain the
packet/byte count of a unidirectional flows. The netflow records are assembled into export
datagrams, with up to 30 records per datagram. A NetFlow collector collects these
datagrams.
The RSA NetFlow collection module can parse both Version 5 and Version netflow export
datagrams.
2. If the NetFlow v5 field has an equivalent v9 field, then the v5 field is mapped to the v9
field.
l The <out> value is the field name that is sent to the RSA Log Decoder.
3 About NetFlow
Event Source Log Configuration Guide
NetFlow Details
This tables describes the NetFlow information.
Format
Index v9 Field v5 Field Description
Format
Index v9 Field v5 Field Description
6 NetFlow Details
Event Source Log Configuration Guide
Format
Index v9 Field v5 Field Description
NetFlow Details 7
Event Source Log Configuration Guide
Format
Index v9 Field v5 Field Description
8 NetFlow Details
Event Source Log Configuration Guide
Format
Index v9 Field v5 Field Description
l Deterministic
Sampling:0x02
NetFlow Details 9
Event Source Log Configuration Guide
Format
Index v9 Field v5 Field Description
10 NetFlow Details
Event Source Log Configuration Guide
Format
Index v9 Field v5 Field Description
NetFlow Details 11
Event Source Log Configuration Guide
Format
Index v9 Field v5 Field Description
12 NetFlow Details
Event Source Log Configuration Guide
Format
Index v9 Field v5 Field Description
NetFlow Details 13
Event Source Log Configuration Guide
Format
Index v9 Field v5 Field Description
14 NetFlow Details
Event Source Log Configuration Guide
Format
Index v9 Field v5 Field Description
NetFlow Details 15
Event Source Log Configuration Guide
Format
Index v9 Field v5 Field Description
16 NetFlow Details
Event Source Log Configuration Guide
CEF Details
This tables lists the CEF information.
Key
Index Key Full Name Description
Format
CEF Details 17
Event Source Log Configuration Guide
Key
Index Key Full Name Description
Format
18 CEF Details
Event Source Log Configuration Guide
Key
Index Key Full Name Description
Format
Example:
“192.168.10.1”
CEF Details 19
Event Source Log Configuration Guide
Key
Index Key Full Name Description
Format
format is MMM
dd yyyy HH:m-
m:ss or mil-
liseconds since
epoch (Jan 1st
1970). An
example would
be reporting the
end of a session.
20 CEF Details
Event Source Log Configuration Guide
Key
Index Key Full Name Description
Format
CEF Details 21
Event Source Log Configuration Guide
Key
Index Key Full Name Description
Format
22 CEF Details
Event Source Log Configuration Guide
Key
Index Key Full Name Description
Format
CEF Details 23
Event Source Log Configuration Guide
Key
Index Key Full Name Description
Format
24 CEF Details
Event Source Log Configuration Guide
Key
Index Key Full Name Description
Format
CEF Details 25
Event Source Log Configuration Guide
Key
Index Key Full Name Description
Format
26 CEF Details
Event Source Log Configuration Guide
Key
Index Key Full Name Description
Format
RSA Details
This table describes the RSA parsing information.
NetWit-
NetWit-
Flow Col- ness
Flow Parser ness
Ind- lector Map- Platform Descrip-
Mapping (rsa- Platform
ex ping Log Map- tion
flowmsg.xml) Network
(netflow.xml) ping
Meta Key
Meta Key
RSA Details 27
Event Source Log Configuration Guide
NetWit-
NetWit-
Flow Col- ness
Flow Parser ness
Ind- lector Map- Platform Descrip-
Mapping (rsa- Platform
ex ping Log Map- tion
flowmsg.xml) Network
(netflow.xml) ping
Meta Key
Meta Key
28 RSA Details
Event Source Log Configuration Guide
NetWit-
NetWit-
Flow Col- ness
Flow Parser ness
Ind- lector Map- Platform Descrip-
Mapping (rsa- Platform
ex ping Log Map- tion
flowmsg.xml) Network
(netflow.xml) ping
Meta Key
Meta Key
regardless
of how
many times
that flag
was seen.
RSA Details 29
Event Source Log Configuration Guide
NetWit-
NetWit-
Flow Col- ness
Flow Parser ness
Ind- lector Map- Platform Descrip-
Mapping (rsa- Platform
ex ping Log Map- tion
flowmsg.xml) Network
(netflow.xml) ping
Meta Key
Meta Key
30 RSA Details
Event Source Log Configuration Guide
NetWit-
NetWit-
Flow Col- ness
Flow Parser ness
Ind- lector Map- Platform Descrip-
Mapping (rsa- Platform
ex ping Log Map- tion
flowmsg.xml) Network
(netflow.xml) ping
Meta Key
Meta Key
bytes
RSA Details 31
Event Source Log Configuration Guide
NetWit-
NetWit-
Flow Col- ness
Flow Parser ness
Ind- lector Map- Platform Descrip-
Mapping (rsa- Platform
ex ping Log Map- tion
flowmsg.xml) Network
(netflow.xml) ping
Meta Key
Meta Key
32 RSA Details
Event Source Log Configuration Guide
NetWit-
NetWit-
Flow Col- ness
Flow Parser ness
Ind- lector Map- Platform Descrip-
Mapping (rsa- Platform
ex ping Log Map- tion
flowmsg.xml) Network
(netflow.xml) ping
Meta Key
Meta Key
interval
RSA Details 33
Event Source Log Configuration Guide
NetWit-
NetWit-
Flow Col- ness
Flow Parser ness
Ind- lector Map- Platform Descrip-
Mapping (rsa- Platform
ex ping Log Map- tion
flowmsg.xml) Network
(netflow.xml) ping
Meta Key
Meta Key
34 RSA Details
Event Source Log Configuration Guide
NetWit-
NetWit-
Flow Col- ness
Flow Parser ness
Ind- lector Map- Platform Descrip-
Mapping (rsa- Platform
ex ping Log Map- tion
flowmsg.xml) Network
(netflow.xml) ping
Meta Key
Meta Key
RSA Details 35
Event Source Log Configuration Guide
NetWit-
NetWit-
Flow Col- ness
Flow Parser ness
Ind- lector Map- Platform Descrip-
Mapping (rsa- Platform
ex ping Log Map- tion
flowmsg.xml) Network
(netflow.xml) ping
Meta Key
Meta Key
36 RSA Details
Event Source Log Configuration Guide
NetWit-
NetWit-
Flow Col- ness
Flow Parser ness
Ind- lector Map- Platform Descrip-
Mapping (rsa- Platform
ex ping Log Map- tion
flowmsg.xml) Network
(netflow.xml) ping
Meta Key
Meta Key
RSA Details 37
Event Source Log Configuration Guide
NetWit-
NetWit-
Flow Col- ness
Flow Parser ness
Ind- lector Map- Platform Descrip-
Mapping (rsa- Platform
ex ping Log Map- tion
flowmsg.xml) Network
(netflow.xml) ping
Meta Key
Meta Key
38 RSA Details
Event Source Log Configuration Guide
NetWit-
NetWit-
Flow Col- ness
Flow Parser ness
Ind- lector Map- Platform Descrip-
Mapping (rsa- Platform
ex ping Log Map- tion
flowmsg.xml) Network
(netflow.xml) ping
Meta Key
Meta Key
address)
RSA Details 39
Event Source Log Configuration Guide
NetWitness
Index enVision Name Platform Failure Key
Name
NetWitness
Index enVision Name Platform Failure Key
Name
NetWitness
Index enVision Name Platform Failure Key
Name
NetWitness
Index enVision Name Platform Failure Key
Name
NetWitness
Index enVision Name Platform Failure Key
Name
NetWitness
Index enVision Name Platform Failure Key
Name
Trademarks
RSA Conference Logo, RSA, and other trademarks, are trademarks of RSA Security LLC or its
affiliates ("RSA"). For a list of RSA trademarks, go to https://www.rsa.com/en-
us/company/rsa-trademarks. Other trademarks are trademarks of their respective owners.