Thanks for that, I also felt it was surprisingly difficult.
So far these are my initial candidates (only the last 2 are FOSS):
So far these are my initial candidates (only the last 2 are FOSS):
- Splunk Enterprise Free License – I struggle to understand if this will support netflow or not, as "Splunk Stream" seems to be additionally required to ingest it.
- ElastiFlow – the free tier supports up to 25 netflow sources, that would be enough in my case.
- openobserve + goflow2
- Akvorado