---
title: "Creating Traffic Flows"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35367017/Creating%20Traffic%20Flows"
format: markdown
---
To add a new traffic flow for the Data Connector, do the following:

1. Log in to the Infoblox Portal.
2. Go to **Integrations** > **Data Connectors**.
3. In the **Traffic Flow Configuration** tab, click **Create Configuration**.
4. Complete the following sections of the **Create New Data Configuration** wizard:
  1. **General**:
    1. **Name**: Enter a name for this configuration.
    2. **Description**: Enter a description to distinguish this Data Connector from other flows. The maximum length of the description is 256 characters.
    3. **State**: Use the slider to enable or disable this configuration. When the configuration is disabled, traffic does not flow.
    4. **Tags**: Click **Add** and specify a key-value pair to associate with the application:
      - **KEY**: Enter a meaningful name for the key, such as a location or department.
      - **VALUE**: Enter a value for that key. For more information, see *[Managing Tags](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35397076)*.
        Click **Next** to proceed.
  2. **Log Source Configuration**:
    1. **Source**: Select a source from among the available source options in the list of sources or click the **Add** icon to create a new source. For information on adding a new traffic flow data configuration source,  see *[Adding a New Traffic Flow Source](https://docs.infoblox.com/space/BloxOneCloud/580616839/Adding+a+New+Traffic+Flow+Source)*. Click **Select** to add the source to the configuration. The source field will be pre-populated when using a marketplace script subscribed to through Infoblox Ecosystem.
      When selecting *Schedule Source* as a source, in the *Scheduler* section, add a valid cron expression.
    2. **Source Configuration**: Click **Add Log Type** to add a log type (dependent on source type) from among the available options; *Audit Log*, *DDI DHCP Lease Log*, *DDI Query/Response Log*, *Internal Notifications*, *Service Log*, *Threat Defense Query/Response Log*, *Threat Defence Threat Feeds Hit Log, IPAM Metadata/DHCP Lease Information, RPZ Logs for Threat Defense,* and *Logs for DDI*.
      **Additional information based on source type:**
      - **Infoblox Cloud Source**: Using Infoblox Cloud Source, you can select Audit Log, Internal Notifications, Service Log, Threat Defense Threat Feeds Hits Log, Threat Defense Query/Response Log, DDI DHCP Lease Log, DDI Query/Response Log.
        The *Add Log Type* options for log source.
        For information on supported log types for **Infoblox Cloud Source**, see *[Log Source Configuration Export Options](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/774964692)* and *[Event Field Logs](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/770310159)*.
      - **CDC-NIOS source**: Using CDC-NIOS source, select IPAM Metadata/DHCP Lease Information, Query/Response Log, or RPZ Logs. When selecting IPAM Metadata/DHCP Lease Information, no management options are available. In the case of IPAM Metadata/DHCP Lease Information, the log types are excluded from the filter configuration options by design. Note that Threat Defense Query/Response Logs from Infoblox Platform Source and RPZ Logs from NIOS Source are not the same.
        For information on supported log types for **CDC-NIOS**, see *[Log Source Configuration Export Options](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/774964692)* and *[Event Field Logs](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/770310159)** *(NIOS DNS Q/R and NIOS RPZ log types).
    3. **Export Fields**: Click the *Manage* link associated with a selected log type to select your export options. For information on the available export options for each log type, see *[Log Source Configuration Export Options](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/774964692)*. When selecting IPAM Metadata/DHCP Lease Information for **CDC-NIOS**, no management options (the *Manage* hyperlink) are available. In this case, the log types are excluded from the filter configuration options.
      
    4. **Filters**: Specify ETL Configurations by adding an ETL filter configuration in the text field.
    5. Click **Next** to continue.

> ℹ️ When customers send service logs from Cloud Data Connector to any destination, service logs that **do not **contain a Service ID will not be forwarded.

**Destination Configuration**:

1. In the *Destination Configuration* pane, select a destination from among the available destination options in the list of destinations or click the **Add** icon to create a new destination. Click **Select** to add the destination to the configuration.
  - When selecting **CDC-NIOS** as the source, select **Infoblox Cloud Source** as the destination.
  - Multiple traffic flows of the same destination type (syslog and HTTP) to the same destination host are supported.
2. Click **Next** to continue.   
For information on adding a new traffic flow data configuration destination, see *[Adding a New Traffic Flow Destination](https://docs.infoblox.com/space/BloxOneCloud/581010569/Adding+a+New+Traffic+Flow+Destination)*.
3. **Service Instance**:  
Choose a service instance from the drop-down menu.
  - **Setting Up a Service instance for Infoblox Ecosystem**: If you have subscribed to the Infoblox Ecosystem, you can choose **Data Connector in Infoblox Cloud** as the service instance. This option allows you to forward logs directly to Microsoft Sentinel and Splunk Cloud using HTTPS. For information, see *[Data Connector HTTP Destination for MSentinel and Splunk (Data Connector to On-prem or Cloud)](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/774931918)*.
  - **Setting Up a Service instance for Cloud-to-Cloud Log Transfer**: To set up Cloud-to-Cloud log transfer, select **Data Connector in Infoblox Cloud** as the service instance. This option allows you to forward logs from cloud to cloud. For information, see *[Cloud-to-Cloud Log Transfer](https://docs.infoblox.com/space/BloxOneCloud/1073381538/Cloud-to-Cloud+Log+Transfer)**.*
4. **Summary**:
  - Review the details of your new traffic flow instance before saving it.
  - Modify a specific configuration: Click the respective section in the navigation on the left or click **Back** to go back to the previous sections.
  - View detailed information for a specific section. For example, Click **Save & Close** to save your configuration or click **Cancel **to discard all the changes you have made.
5. To view your created traffic flows on the **Data Connector Traffic Flows** tab in the Infoblox Portal, go to **Integrations** > **Data Connectors** > **Traffic Flow**.

You can also perform the following operations on the wizard page: 

- **Help:** Click **Help** to open the contextual help window and display information about the wizard. Click **Help** again to close the contextual help window.
- **Cancel:** Click **Cancel** to cancel the current configuration operation and return to the *Traffic Flow* page.