Layer2 traffic analysis can be performed by integrating flow into Logsign.
Note that: Netflow configuration varies according to different vendors.
For netflow configuration on the devices, the port must be mirrored and the datas should be forwarded to the Logsign Unified SecOps Platform IP address over UDP, on the port that matches the flow format exported by the device: port 2056 for NetFlow V5, port 2055 for NetFlow V9 and IPFIX (SFlow uses port 6343). After configuration, netflow integration can be performed by clicking the “+ Device” button from “Data Collection” tab on Logsign Unified SecOps Platform.
Netflow is selected as the integration type and the necessary information is entered in the relevant fields. In the Flow Type field, choose the format your device exports (NetFlow V5, NetFlow V9, IPFIX or SFlow). The Port field is filled in automatically from this choice and cannot be edited. Then click on the save button.
IPFIX records are accepted from Logsign version 6.4.119 onwards. On earlier versions the IPFIX packets reach the platform, but the logsign-flowd service discards every record with an "Unknown flow data type" error, so no events show up for the source.
To check whether the configuration is done correctly, the flow port can be tracked with the following command on the cli. The example below uses port 2056 (NetFlow V5); for NetFlow V9 and IPFIX sources track port 2055 instead.