{"id":14936,"date":"2025-06-12T12:41:34","date_gmt":"2025-06-12T06:41:34","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=14936"},"modified":"2025-06-12T12:41:34","modified_gmt":"2025-06-12T06:41:34","slug":"axoflow-zero-to-hero-stream-security-data-anywhere","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/axoflow-zero-to-hero-stream-security-data-anywhere\/","title":{"rendered":"Axoflow Zero to Hero: Stream Security Data Anywhere"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-14938 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2025\/06\/67d84ba300bf1692610aac74_980x613_top_4_tricks_to_reduce_SIEM_data_volume-1-1.webp\" alt=\"\" width=\"1960\" height=\"1226\" \/><\/p>\n<p>Today we&#8217;re going to show you how to be a hero by connecting machines and logging data to your analytics tool of choice in 12 minutes or less using the\u00a0Axoflow Platform.<\/p>\n<figure class=\"w-richtext-align-fullwidth w-richtext-figure-type-video\">\n<div><iframe title=\"Axoflow Zero to Hero: Stream Log Data to Splunk in Under 12 Minutes with Mark Bonsack 1\" src=\"https:\/\/www.youtube.com\/embed\/iJ91iMz0CiU\" frameborder=\"0\" scrolling=\"no\" allowfullscreen=\"allowfullscreen\" data-mce-fragment=\"1\"><\/iframe><\/div>\n<\/figure>\n<h2><\/h2>\n<h2><\/h2>\n<h2><strong>What you&#8217;ll need<\/strong><\/h2>\n<p>To follow the steps shown in the\u00a0video, you&#8217;ll need:<\/p>\n<ul role=\"list\">\n<li>A virtual machine<\/li>\n<li>Evaluation access to Axoflow. You can\u00a0submit an evaluation request, we&#8217;ll set it up for you within a business day.<\/li>\n<li>Access to Splunk and a token to send data to Splunk, or another\u00a0destination supported by Axoflow.<\/li>\n<\/ul>\n<h2><\/h2>\n<h2><\/h2>\n<h2><strong>Install AxoRouter<\/strong><\/h2>\n<div class=\"w-embed w-iframe\"><iframe loading=\"lazy\" title=\"Axoflow Zero to Hero: Stream Log Data to Splunk in Under 12 Minutes with Mark Bonsack 1\" src=\"https:\/\/www.youtube.com\/embed\/iJ91iMz0CiU?start=42\" width=\"100%\" height=\"100%\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\" data-mce-fragment=\"1\"><\/iframe><\/div>\n<p>The first step in testing the Axoflow Console is to install AxoRouter.\u00a0AxoRouter\u00a0is the curation solution that collects, aggregates, transforms, and routes all kinds of security data automatically \u2013 at carrier-grade scale.<\/p>\n<ol role=\"list\">\n<li>Open your Axoflow Console, and select the\u00a0<strong>Provisioning<\/strong>\u00a0page.<\/li>\n<li>Click\u00a0<strong>Select type and platform &gt; AxoRouter &gt; Linux &gt; Copy and close<\/strong>.<\/li>\n<li>Open a terminal on your VM, then paste the install command.<\/li>\n<li>Reload the\u00a0<strong>Provisioning<\/strong>\u00a0page. The new AxoRouter deployment shows up.<\/li>\n<li>Click the check mark.<\/li>\n<li>Add a custom label to your AxoRouter so you&#8217;ll know which team it belongs to, then click\u00a0<strong>Register<\/strong>.<\/li>\n<\/ol>\n<p>After you register an AxoRouter deployment, you can see which operating system that you&#8217;re running on, and some other details of the host.<\/p>\n<h2><\/h2>\n<h2><\/h2>\n<h2><strong>Send data to AxoRouter<\/strong><\/h2>\n<p>If you have a data source handy, configure it to\u00a0send logs to AxoRouter. If you don\u2019t, open a terminal on your VM running AxoRouter, and run the following command to generate some synthetic data.<\/p>\n<p>Note that AxoRouter collects detailed, real-time metrics about the data-flows \u2013 giving you observability over the health of the security data pipeline and its components. Your security data remains in your self-managed cloud or in your on-prem instance where your sources, destinations, and AxoRouters are running, only metrics are forwarded to Axoflow Console.<\/p>\n<pre class=\"w-code-block\" contenteditable=\"false\"><code class=\"language-shell\">for i in `seq 1 120`; do echo \"&lt;165&gt; fortigate date=$(date -u +%Y-%m-%d) time=$(date -u +\"%H:%M:%S%Z\") devname=us-east-1-dc1-a-dmz-fw devid=FGT60D4614044725 logid=0100040704 type=event subtype=system level=notice vd=root logdesc=\\\"System performance statistics\\\" action=\\\"perf-stats\\\" cpu=2 mem=35 totalsession=61 disk=2 bandwidth=158\/138 setuprate=2 disklograte=0 fazlograte=0 msg=\\\"Performance statistics: average CPU: 2, memory: 35, concurrent sessions: 61, setup-rate: 2\\\"\"; sleep 0.5; echo \"&lt;165&gt;  id=us-west-1-dc1-a-dmz-fw sn=C0EFE3336C80 time=\\\"$(date -u +\"%Y-%m-%d %H:%M:%S %Z\")\\\" fw=192.168.1.239 pri=6 c=1024 gcat=6 m=537 msg=\\\"Connection Closed\\\" srcMac=00:50:56:f5:50:27 src=10.237.228.74:54406:X20 srcZone=Trusted natSrc=192.168.1.239:38377 dstMac=00:1a:f0:8b:e0:18 dst=44.190.129.212:123:X2 dstZone=Untrusted natDst=44.190.129.212:123 proto=udp\/ntp sent=152 rcvd=152 spkt=2 rpkt=2 cdur=30250 rule=\\\"22 (LAN-&gt;WAN)\\\" n=490872197 fw_action=\\\"NA\\\" dpi=0\"; sleep 0.5; echo \"&lt;165&gt;$(date -u +\"%b%e %H:%M:%S\") us-east-1-dc1-b-edge-fw 1,$(date -u +\"%Y\/%m\/%d %H:%M:%S\"),007200001056,TRAFFIC,end,1,$(date -u +\"%Y\/%m\/%d %H:%M:%S\"),192.168.41.30,192.168.41.255,10.193.16.193,192.168.41.255,allow-all,,,netbios-ns,vsys1,Trust,Untrust,ethernet1\/1,ethernet1\/2,To-Panorama,$(date -u +\"%Y\/%m\/%d %H:%M:%S\"),8720,1,137,137,11637,137,0x400000,udp,allow,276,276,0,3,$(date -u +\"%Y\/%m\/%d %H:%M:%S\"),2,any,0,2800265,0x0,192.168.0.0-192.168.255.255,192.168.0.0-192.168.255.255,0,3,0\"; sleep 0.5; done | nc -v 127.0.0.1 514<\/code><button class=\"copy-button\">Copy<\/button><\/pre>\n<p>Wait a few seconds to give some time for the metrics to accumulate.<\/p>\n<h2><\/h2>\n<h2><\/h2>\n<h2><strong>Check analytics data<\/strong><\/h2>\n<div class=\"w-embed w-iframe\"><iframe loading=\"lazy\" title=\"Axoflow Zero to Hero: Stream Log Data to Splunk in Under 12 Minutes with Mark Bonsack 1\" src=\"https:\/\/www.youtube.com\/embed\/iJ91iMz0CiU?start=175\" width=\"100%\" height=\"100%\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\" data-mce-fragment=\"1\"><\/iframe><\/div>\n<p>Select\u00a0<strong>Analytics<\/strong>\u00a0(if you&#8217;ve navigated away, select\u00a0<strong>Topology &gt; your-AxoRouter&gt;<\/strong>\u00a0first)<br \/>\nIf your AxoRouter is receiving data, some metrics should be visible. AxoRouter automatically classifies and parses the incoming data, and adds vendor and product labels to the data it recognizes.<\/p>\n<p>One of the cool things you&#8217;ll see is that there are a number of metrics that we collect in the AxoRouter, in the collector itself. First and foremost, you&#8217;ll see that we are detecting what product is sending this particular set of data.<\/p>\n<p>If you change back to the\u00a0<strong>Overview<\/strong>\u00a0tab, you can see that Axoflow raised a warning for this AxoRouter, because there are no flows configured for this particular router: right now we&#8217;re collecting the data, but we&#8217;re not sending it anywhere. Let&#8217;s fix that by creating a destination.<\/p>\n<h2><\/h2>\n<h2><\/h2>\n<h2><strong>Create destination<\/strong><\/h2>\n<div class=\"w-embed w-iframe\"><iframe loading=\"lazy\" title=\"Axoflow Zero to Hero: Stream Log Data to Splunk in Under 12 Minutes with Mark Bonsack 1\" src=\"https:\/\/www.youtube.com\/embed\/iJ91iMz0CiU?start=279\" width=\"100%\" height=\"100%\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\" data-mce-fragment=\"1\"><\/iframe><\/div>\n<p>Create a Splunk destination. If you don\u2019t want to use Splunk, use another\u00a0destination supported by Axoflow.<\/p>\n<ol role=\"list\">\n<li>Select\u00a0<strong>Topology &gt; + &gt; Destination &gt; Splunk<\/strong>.<\/li>\n<li>Enter the required parameters. You&#8217;ll need the URL of your Splunk deployment, and an access token that allows you to send data (you can get these from your Splunk administrator).<\/li>\n<li>Click\u00a0<strong>Create<\/strong>.<\/li>\n<\/ol>\n<h2><\/h2>\n<h2><\/h2>\n<h2><strong>Create a flow<\/strong><\/h2>\n<div class=\"w-embed w-iframe\"><iframe loading=\"lazy\" title=\"Axoflow Zero to Hero: Stream Log Data to Splunk in Under 12 Minutes with Mark Bonsack 1\" src=\"https:\/\/www.youtube.com\/embed\/iJ91iMz0CiU?start=375\" width=\"100%\" height=\"100%\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\" data-mce-fragment=\"1\"><\/iframe><\/div>\n<p>Create a flow to route the data received by AxoRouter to your Splunk destination.<\/p>\n<ol role=\"list\">\n<li>Select\u00a0<strong>Flows &gt; Create New Flow<\/strong>.<\/li>\n<li>Enter a name for the flow.<\/li>\n<li>In the\u00a0<strong>Router Selector<\/strong>\u00a0field select the name of your AxoRouter.<\/li>\n<li>Set the\u00a0<strong>Destination<\/strong>\u00a0field to your Splunk destination, then click\u00a0<strong>Create<\/strong>.<\/li>\n<\/ol>\n<h2><\/h2>\n<h2><\/h2>\n<h2><strong>Add a source<\/strong><\/h2>\n<div class=\"w-embed w-iframe\"><iframe loading=\"lazy\" title=\"Axoflow Zero to Hero: Stream Log Data to Splunk in Under 12 Minutes with Mark Bonsack 1\" src=\"https:\/\/www.youtube.com\/embed\/iJ91iMz0CiU?start=476\" width=\"100%\" height=\"100%\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\" data-mce-fragment=\"1\"><\/iframe><\/div>\n<p>If you go back to the\u00a0<strong>Topology<\/strong>\u00a0page, you&#8217;re going to see that there is a connection between your AxoRouter and your destination. To visualize the sources, register the sources that are sending data to the AxoRouter.<\/p>\n<ol role=\"list\">\n<li>Select\u00a0<strong>Topology &gt; + &gt; Source &gt; Detected<\/strong>. The list of sources that are currently sending data and AxoRouter has automatically recognized are displayed.<br \/>\nNOTE:\u00a0If you don&#8217;t have separate source hosts and you&#8217;re sending data with the script provided above, only a single source will be detected, since all data is coming from the same IP\u00a0address. However, it will show up as three different hosts and source types, because AxoRouter classifies the incoming messages based on their content.<\/li>\n<li>Select a source, then add a custom label to the source if you&#8217;d like to.<\/li>\n<\/ol>\n<p>Once everything is set up, the source and metrics about the data it&#8217;s sending shows up on the\u00a0<strong>Topology<\/strong>\u00a0page. So in addition to the deeper level analytics, you get a high level view of what is happening on the topology level.<\/p>\n<h2><\/h2>\n<h2><\/h2>\n<h2><strong>Check output metrics<\/strong><\/h2>\n<div class=\"w-embed w-iframe\"><iframe loading=\"lazy\" title=\"Axoflow Zero to Hero: Stream Log Data to Splunk in Under 12 Minutes with Mark Bonsack 1\" src=\"https:\/\/www.youtube.com\/embed\/iJ91iMz0CiU?start=555\" width=\"100%\" height=\"100%\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\" data-mce-fragment=\"1\"><\/iframe><\/div>\n<p>Let\u2019s take a look at output events:<\/p>\n<p>Click on your AxoRouter and select\u00a0<strong>Analytics<\/strong>, then change the\u00a0<strong>Input events<\/strong>\u00a0to\u00a0<strong>Output events<\/strong>.<\/p>\n<p>Now that AxoRouter is receiving data from a source and a destination to forward it, you&#8217;ll see that the output metrics are also populated. In addition to the metrics collected earlier, such as the destination port and the transport, now you see another metrics dimension called Splunk source type. Since we selected Splunk as a destination, Axoflow automatically sets the source type to the right values.<\/p>\n<p>For example, using labels you can check how traffic is distributed based on\u00a0<strong>splunk_sourcetype<\/strong>, or to which index data is sent using the\u00a0<strong>splunk_index<\/strong>\u00a0label.<\/p>\n<p>So now let&#8217;s go look at Splunk itself and see what this data looks like.<\/p>\n<h2><\/h2>\n<h2><\/h2>\n<h2><strong>Check data in Splunk<\/strong><\/h2>\n<div class=\"w-embed w-iframe\"><iframe loading=\"lazy\" title=\"Axoflow Zero to Hero: Stream Log Data to Splunk in Under 12 Minutes with Mark Bonsack 1\" src=\"https:\/\/www.youtube.com\/embed\/iJ91iMz0CiU?start=608\" width=\"100%\" height=\"100%\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\" data-mce-fragment=\"1\"><\/iframe><\/div>\n<p>Since AxoRouter takes care of parsing, classifying, and sending the data to Splunk, you don&#8217;t need to do that on the Splunk side: you don\u2019t need technology add-ons or parsers in Splunk. You can simply use the structured data and metadata that AxoRouter provides to dig into your data, create charts and graphs, and gain insights.<\/p>\n<h2><\/h2>\n<h2><\/h2>\n<h2>Summary<\/h2>\n<p>If you\u2019ve successfully followed this blog or the related video, you&#8217;ll already have some useful data in your analytics tool. We spent less than 12 minutes doing all this, and didn\u2019t need to invoke or write a regular expression parser the whole time.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>About DT Asia<\/strong><\/p>\n<p>DT Asia began in 2007 with a clear mission to build the market entry for various pioneering IT security solutions from the US, Europe and Israel.<\/p>\n<p>Today, DT Asia is a regional, value-added distributor of cybersecurity solutions providing cutting-edge technologies to key government organisations and top private sector clients including global banks and Fortune 500 companies. We have offices and partners around the Asia Pacific to better understand the markets and deliver localised solutions.<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>How we help<\/strong><\/p>\n<p>If you need to know more about how to be a hero by connecting machines and logging data to your analytics tool of choice in 12 minutes or less using the Axoflow Platform, you\u2019re in the right place, we\u2019re here to help! DTA is Axoflow\u2019s distributor, especially in Singapore and Asia, our technicians have deep experience on the product and relevant technologies you can always trust, we provide this product\u2019s turnkey solutions, including consultation, deployment, and maintenance service.<\/p>\n<p>Click here and here and here to know more:\u00a0<a href=\"https:\/\/dtasiagroup.com\/vi\/axoflow\/\">https:\/\/dtasiagroup.com\/axoflow\/<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Today we&#8217;re going to show you how to be a hero by connecting machines and logging data to your analytics tool of choice in 12 minutes or less using the\u00a0Axoflow Platform.<\/p>","protected":false},"author":11,"featured_media":14938,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-14936","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14936","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=14936"}],"version-history":[{"count":3,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14936\/revisions"}],"predecessor-version":[{"id":14964,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14936\/revisions\/14964"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/14938"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=14936"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=14936"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=14936"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}