SFTP / network file shares
SFTP servers, SMB/CIFS shares, NFS mounts.
Access mode: Read-only (typically)
Required information
| Field | Details |
|---|---|
| Protocol | SFTP, SCP, FTPS, SMB/CIFS, or NFS. |
| Host / IP | Server FQDN or IP. |
| Port | SFTP: 22. SMB: 445. NFS: 2049. FTPS: 990 or 21. |
| Path(s) | Remote directories/paths to access. |
| Credentials | SFTP: SSH key or password. SMB: domain\user + password. NFS: IP-based + UID/GID mapping. |
Network considerations
Almost always on-premises or in a DMZ. VPN required in most cases.
SFTP: Port 22. May be on a non-standard port. SSH key exchange must be compatible.
SMB/CIFS: Port 445. Typically internal-only. VPN + domain authentication.
NFS: Port 2049. IP-based access control. Must be on same network or VPN.
FTPS (explicit/implicit): Ports 990 or 21 + passive port range. Firewalls must allow passive port range.
Credential and auth management
Preferred (SFTP): SSH key auth. Flume generates keypair, provides public key. No password to rotate.
Acceptable (SFTP): Password auth. Over encrypted SSH channel.
SMB/CIFS: Domain credentials (AD account). Kerberos preferred over NTLM.
NFS: Typically IP-based access control + UID/GID mapping. No password auth.
Host key verification: Flume validates server host key on first connection. Provide expected host key fingerprint.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Network reachability | telnet <host> <port> | Connected |
| Authentication | sftp <user>@<host> or mount test | Logged in / mounted |
| Directory listing | ls <remote_path> | Lists expected files |
| File read | Download a sample file | File content readable |
| Permission check | Attempt write (should fail for read-only) | Permission denied confirms read-only |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.