<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stream app - Netflowreceiver problem in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352332#M66646</link>
    <description>&lt;P&gt;I think we've gone far enough in this one question, perhaps that could be a new question or perhaps Splunk support might help here.&lt;/P&gt;

&lt;P&gt;I'd suspect the Splunk server your using doesn't have access to the indexes containing the relevant data however at this point I am guessing!&lt;/P&gt;</description>
    <pubDate>Sun, 25 Mar 2018 00:30:10 GMT</pubDate>
    <dc:creator>gjanders</dc:creator>
    <dc:date>2018-03-25T00:30:10Z</dc:date>
    <item>
      <title>Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352312#M66626</link>
      <description>&lt;P&gt;Hi There, I've configured the stream app and streamfwd.log as follow: &lt;/P&gt;

&lt;P&gt;netflowReceiver.0.ip = 192.168.1.2&lt;BR /&gt;
netflowReceiver.0.port = 9996&lt;BR /&gt;
netflowReceiver.0.protocol = udp&lt;BR /&gt;
netflowReceiver.0.decoder = netflow&lt;/P&gt;

&lt;P&gt;UDP Netflow is coming in on the splunk server, confirmed with TCPDUMP&lt;/P&gt;

&lt;P&gt;However, I don't get the netflow data and see these kinds of errors in streamfwd.log:&lt;/P&gt;

&lt;P&gt;Caught exception in openDatagramListenersystem:99 bind&lt;BR /&gt;
 Unable to start any Netflow Receivers&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 09:10:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352312#M66626</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2018-03-14T09:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352313#M66627</link>
      <description>&lt;P&gt;Can you provide &lt;CODE&gt;inputs.conf&lt;/CODE&gt; ?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 12:34:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352313#M66627</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-03-14T12:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352314#M66628</link>
      <description>&lt;P&gt;Local: &lt;/P&gt;

&lt;P&gt;[streamfwd://streamfwd]&lt;BR /&gt;
splunk_stream_app_location = &lt;A href="http://localhost:8000/en-us/custom/splunk_app_stream/" target="_blank"&gt;http://localhost:8000/en-us/custom/splunk_app_stream/&lt;/A&gt;&lt;BR /&gt;
stream_forwarder_id =&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;Default:&lt;/P&gt;

&lt;P&gt;[streamfwd]&lt;BR /&gt;
disabled = true&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:26:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352314#M66628</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2020-09-29T18:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352315#M66629</link>
      <description>&lt;P&gt;Was this inputs.conf sufficient in order to proceed?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 17:11:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352315#M66629</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2018-03-15T17:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352316#M66630</link>
      <description>&lt;P&gt;Is this inputs.conf sufficient to proceed?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 17:12:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352316#M66630</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2018-03-15T17:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352317#M66631</link>
      <description>&lt;P&gt;Hello there?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 14:45:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352317#M66631</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2018-03-16T14:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352318#M66632</link>
      <description>&lt;P&gt;Anyone out there?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 16:08:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352318#M66632</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2018-03-19T16:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352319#M66633</link>
      <description>&lt;P&gt;Is this an independent stream forwarder and are you running the process as root? Or as a non-root user?&lt;BR /&gt;
Also you have a Splunk instance with the webgui enabled and the stream application on the same host?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 08:17:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352319#M66633</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2018-03-21T08:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352320#M66634</link>
      <description>&lt;P&gt;Yes, Everything, the Splunk instance with the web gui, the stream application is installed on one host. &lt;BR /&gt;
The process runs as root. &lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 08:28:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352320#M66634</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2018-03-21T08:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352321#M66635</link>
      <description>&lt;P&gt;Ok so the IP 192.168.1.2 is configured on the server?&lt;BR /&gt;
Does netstat -an | grep 9996 show anything listening on that port?&lt;/P&gt;

&lt;P&gt;I do not see netflowReceiver.0.protocol = udp as a mentioned line in &lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.1.1/DeployStreamApp/ConfigureFlowcollector"&gt;Configure netflow collector&lt;/A&gt; but not sure if that is making any difference here (netflow is normally udp so you should be able to drop this line).&lt;/P&gt;

&lt;P&gt;Finally when you said:&lt;BR /&gt;
"Hi There, I've configured the stream app and streamfwd.log as follow: ", I assume you mean streamfwd.conf ?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 10:58:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352321#M66635</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2018-03-21T10:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352322#M66636</link>
      <description>&lt;P&gt;The 192.168.1.2 is the ip address of the firewall which is sending the netflow information to Splunk machine.&lt;/P&gt;

&lt;P&gt;Output on splunk: udp        0      0 0.0.0.0:9996            0.0.0.0:*&lt;/P&gt;

&lt;P&gt;Yes offcourse streamfwd.conf &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 11:28:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352322#M66636</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2018-03-21T11:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352323#M66637</link>
      <description>&lt;P&gt;netflowReceiver.0.ip = should be the IP of the &lt;EM&gt;host&lt;/EM&gt; listening for the data (i.e. your server), not the IP of the server sending the data...&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 21:08:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352323#M66637</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2018-03-21T21:08:41Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352324#M66638</link>
      <description>&lt;P&gt;Also can you run a netstat -anp | grep 9996 &lt;BR /&gt;
That should show you what process is using 9996&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 21:28:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352324#M66638</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2018-03-21T21:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352325#M66639</link>
      <description>&lt;P&gt;NetflowReceiver.0.ip -&amp;gt; Splunk host? OK, thx I'll try and make that correction. &lt;/P&gt;

&lt;P&gt;Output netstat -anp | grep 9996 : &lt;/P&gt;

&lt;P&gt;tcp        0      0 0.0.0.0:9996            0.0.0.0:*               LISTEN      9685/splunkd&lt;BR /&gt;
udp        0      0 0.0.0.0:9996            0.0.0.0:*                           12482/nfcapd&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 07:07:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352325#M66639</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2018-03-22T07:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352326#M66640</link>
      <description>&lt;P&gt;I've altered the streamfwd.conf file to and point the netflowreceiver.0.ip to my splunk host where the UDP 9996 is landed. However, even when I try to put in the local ip address or the loopback address, I see this error in streamfwd.log:&lt;/P&gt;

&lt;P&gt;2018-03-22 09:20:48 INFO  &lt;A href="CaptureServer.cpp:1926"&gt;140441626711808&lt;/A&gt; stream.CaptureServer - Starting data capture&lt;BR /&gt;
2018-03-22 09:20:48 INFO  &lt;A href="https://community.splunk.com/SnifferReactor/SnifferReactor.cpp:161"&gt;140441626711808&lt;/A&gt; stream.SnifferReactor - Starting network capture: sniffer&lt;BR /&gt;
2018-03-22 09:20:48 ERROR &lt;A href="https://community.splunk.com/NetflowManager/NetflowReceiver.hpp:231"&gt;140441626711808&lt;/A&gt; stream.NetflowReceiver - Caught exception in openDatagramListenersystem:98 bind: Address already in use&lt;BR /&gt;
2018-03-22 09:20:48 FATAL &lt;A href="CaptureServer.cpp:2234"&gt;140441626711808&lt;/A&gt; stream.CaptureServer - NetflowManager - Unable to start any Netflow Receivers&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 12:04:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352326#M66640</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2018-03-22T12:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352327#M66641</link>
      <description>&lt;P&gt;Ok so try a different port number (just as a test obviously)&lt;BR /&gt;
netstat -anp | grep 9996 should show you which process is already in use, based on your previous post:&lt;BR /&gt;
udp 0 0 0.0.0.0:9996 0.0.0.0: 12482/nfcapd&lt;/P&gt;

&lt;P&gt;If you ps -ef | grep 12482&lt;BR /&gt;
You will get some more detail&lt;/P&gt;

&lt;P&gt;What is nfcapd? I googled it and it advises it is already capturing network traffic for stream...you will either need to switch port on the stream receiver or stop nfcapd to run the stream on port 9996&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 21:14:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352327#M66641</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2018-03-22T21:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352328#M66642</link>
      <description>&lt;P&gt;Thanks, I had another monitoring application configured to collect netflow data indeed &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
So I deleted that application and restarted splunkd. &lt;BR /&gt;
Now I'm getting this in the logs: &lt;/P&gt;

&lt;P&gt;domain id 1 from device 192.168.1.2 . Dropping flow data set of size 76&lt;BR /&gt;
2018-03-23 09:54:56 WARN  &lt;A href="https://community.splunk.com/NetflowManager/NetflowDecoder.cpp:1112"&gt;140372033984256&lt;/A&gt; stream.NetflowReceiver - NetFlowDecoder::decodeFlow Unable to decode flow set data. No template with id 262 received for observation domain id 1 from device 192.168.1.2 . Dropping flow data set of size 76&lt;BR /&gt;
2018-03-23 09:54:56 WARN  &lt;A href="https://community.splunk.com/NetflowManager/NetflowDecoder.cpp:1112"&gt;140372033984256&lt;/A&gt; stream.NetflowReceiver - NetFlowDecoder::decodeFlow Unable to decode flow set data. No template with id 262 received for observation domain id 1 from device 192.168.1.2 . Dropping flow data set of size 76&lt;BR /&gt;
2018-03-23 09:54:56 WARN  &lt;A href="https://community.splunk.com/NetflowManager/NetflowDecoder.cpp:1112"&gt;140372033984256&lt;/A&gt; stream.NetflowReceiver - NetFlowDecoder::decodeFlow Unable to decode flow set data. No template with id 262 received for observation domain id 1 from device 192.168.1.2 . Dropping flow data set of size 76&lt;BR /&gt;
2018-03-23 09:54:56 WARN  &lt;A href="https://community.splunk.com/NetflowManager/NetflowDecoder.cpp:1112"&gt;140372033984256&lt;/A&gt; stream.NetflowReceiver - NetFlowDecoder::decodeFlow Unable to decode flow set data. No template with id 262 received for observation domain id 1 from device 192.168.1.2 . Dropping flow data set of size 76&lt;BR /&gt;
2018-03-23 09:54:56 WARN  &lt;A href="https://community.splunk.com/NetflowManager/NetflowDecoder.cpp:1112"&gt;140372033984256&lt;/A&gt; stream.NetflowReceiver - NetFlowDecoder::decodeFlow Unable to decode flow set data. No template with id 262 received for observation domain id 1 from device 192.168.1.2 . Dropping flow data set of size 76&lt;BR /&gt;
2018-03-23 09:54:56 WARN  &lt;A href="https://community.splunk.com/NetflowManager/NetflowDecoder.cpp:1112"&gt;140372033984256&lt;/A&gt; stream.NetflowReceiver - NetFlowDecoder::decodeFlow Unable to decode flow set data. No template with id 262 received for observation domain id 1 from device 192.168.1.2 . Dropping flow data set of size 76&lt;BR /&gt;
2018-03-23 09:54:56 WARN  &lt;A href="https://community.splunk.com/NetflowManager/NetflowDecoder.cpp:1112"&gt;140372033984256&lt;/A&gt; stream.NetflowReceiver - NetFlowDecoder::decodeFlow Unable to decode flow set data. No template with id 262 received for observation domain id 1 from device 192.168.1.2 . Dropping flow data set of size 76&lt;BR /&gt;
2018-03-23 09:54:56 WARN  &lt;A href="https://community.splunk.com/NetflowManager/NetflowDecoder.cpp:1112"&gt;140372033984256&lt;/A&gt; stream.NetflowReceiver - NetFlowDecoder::decodeFlow Unable to decode flow set data. No template with id 262 received for observation domain id 1 from device 192.168.1.2 . Dropping flow data set of size 76&lt;BR /&gt;
2018-03-23 09:54:56 WARN  &lt;A href="https://community.splunk.com/NetflowManager/NetflowDecoder.cpp:1112"&gt;140372033984256&lt;/A&gt; stream.NetflowReceiver - NetFlowDecoder::decodeFlow Unable to decode flow set data. No template with id 262 received for observation domain id 1 from device 192.168.1.2 . Dropping flow data set of size 76&lt;/P&gt;

&lt;P&gt;Obviously 192.168.1.2 is the device SENDING netflow data to the splunk host. &lt;BR /&gt;
It looks like it's sending but the data is bounced because of some misconfiguration somewhere...&lt;/P&gt;</description>
      <pubDate>Fri, 23 Mar 2018 09:02:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352328#M66642</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2018-03-23T09:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352329#M66643</link>
      <description>&lt;P&gt;I believe I have answered your original question so moving this discussion into an answer.&lt;/P&gt;

&lt;P&gt;From what I found, the errors relate to netflow v9 data and I &lt;STRONG&gt;believe&lt;/STRONG&gt; it relates to the netflowElement configuration in the &lt;A href="https://docs.splunk.com/Documentation/StreamApp/latest/DeployStreamApp/streamfwd.conf"&gt;streamfwd.conf config file&lt;/A&gt; , however in my environment the relevant team switched back to an earlier netflow protocol that did not have these template id data (V7 from memory) and then it just worked...so I never used the netflowElement setup.&lt;/P&gt;

&lt;P&gt;Good luck!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Mar 2018 23:34:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352329#M66643</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2018-03-23T23:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352330#M66644</link>
      <description>&lt;P&gt;The thing is now that I've deleted the other collector application, netflow data is coming in :&lt;/P&gt;

&lt;P&gt;sourcetype="stream.netflow"&lt;/P&gt;

&lt;P&gt;3/24/18&lt;BR /&gt;
1:04:26.190 PM&lt;BR /&gt;&lt;BR /&gt;
{   [-] &lt;BR /&gt;
     app:&lt;BR /&gt;&lt;BR /&gt;
     bytes:  0&lt;BR /&gt;&lt;BR /&gt;
     count:  1&lt;BR /&gt;&lt;BR /&gt;
     dest_ip:    8.8.8.8&lt;BR /&gt;&lt;BR /&gt;
     dest_port:  53 &lt;BR /&gt;
     drop_packet_count:  0&lt;BR /&gt;&lt;BR /&gt;
     endtime:    2018-03-24T12:04:26.190502Z&lt;BR /&gt;&lt;BR /&gt;
     packets:    0&lt;BR /&gt;&lt;BR /&gt;
     packets_in:     1&lt;BR /&gt;&lt;BR /&gt;
     packets_out:    1&lt;BR /&gt;&lt;BR /&gt;
     src_ip:     192.168.1.2&lt;BR /&gt;&lt;BR /&gt;
     src_mac:&lt;BR /&gt;&lt;BR /&gt;
     src_port:   54808&lt;BR /&gt;&lt;BR /&gt;
     sum(bytes_in):  73 &lt;BR /&gt;
     sum(bytes_out):     73 &lt;BR /&gt;
     timestamp:  2018-03-24T12:04:26.190502Z&lt;BR /&gt;&lt;BR /&gt;
}&lt;BR /&gt;
Show as raw text&lt;/P&gt;

&lt;P&gt;However, when i click the Stream application nothing is shown in the dashboard, analytics overview or flow visualization. -&amp;gt; No results found.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:38:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352330#M66644</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2020-09-29T18:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: Stream app - Netflowreceiver problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352331#M66645</link>
      <description>&lt;P&gt;The thing is now that I've deleted the other collector application, netflow data is coming in :&lt;/P&gt;

&lt;P&gt;sourcetype="stream.netflow"&lt;/P&gt;

&lt;P&gt;3/24/18&lt;BR /&gt;
1:04:26.190 PM &lt;BR /&gt;
{ [-] &lt;BR /&gt;
app: &lt;BR /&gt;
bytes: 0 &lt;BR /&gt;
count: 1 &lt;BR /&gt;
dest_ip: 8.8.8.8 &lt;BR /&gt;
dest_port: 53 &lt;BR /&gt;
drop_packet_count: 0 &lt;BR /&gt;
endtime: 2018-03-24T12:04:26.190502Z &lt;BR /&gt;
packets: 0 &lt;BR /&gt;
packets_in: 1 &lt;BR /&gt;
packets_out: 1 &lt;BR /&gt;
src_ip: 192.168.1.2 &lt;BR /&gt;
src_mac: &lt;BR /&gt;
src_port: 54808 &lt;BR /&gt;
sum(bytes_in): 73 &lt;BR /&gt;
sum(bytes_out): 73 &lt;BR /&gt;
timestamp: 2018-03-24T12:04:26.190502Z &lt;BR /&gt;
}&lt;BR /&gt;
Show as raw text&lt;/P&gt;

&lt;P&gt;However, when i click the Stream application nothing is shown in the dashboard, analytics overview or flow visualization. -&amp;gt; No results found.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:39:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Stream-app-Netflowreceiver-problem/m-p/352331#M66645</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2020-09-29T18:39:02Z</dc:date>
    </item>
  </channel>
</rss>

