<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to decode netflow_elements Key Values pair? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-decode-netflow-elements-Key-Values-pair/m-p/595201#M76693</link>
    <description>&lt;P&gt;I have a similar challenge - just a different source. Did anyone find an suitable approach?&lt;/P&gt;&lt;P&gt;netflow_elements: [ [-]&lt;BR /&gt;5951.638 : 0000&lt;BR /&gt;5951.352 : 0002&lt;BR /&gt;5951.353 : 2a91b70a&lt;BR /&gt;]&lt;/P&gt;</description>
    <pubDate>Mon, 25 Apr 2022 13:01:40 GMT</pubDate>
    <dc:creator>Stan816</dc:creator>
    <dc:date>2022-04-25T13:01:40Z</dc:date>
    <item>
      <title>How to decode netflow_elements Key Values pair?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-decode-netflow-elements-Key-Values-pair/m-p/446673#M54965</link>
      <description>&lt;P&gt;I have configured splunk stream app to collect netflow data from network.&lt;BR /&gt;
Incoming data is being collected and indexed well, however some fields in search output are shown as below:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;input_snmpidx:   6  
netflow_elements:   [   [-] 
         UNKNOWN : 0ab132f5 
         UNKNOWN : 0ab1320b 
         UNKNOWN : 9f99 
         UNKNOWN : 00a1 
         UNKNOWN : 02   
         UNKNOWN : 07e9 
    ]   
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Netflow exporter device is Cisco ASA Version 8.4(4)1.&lt;BR /&gt;
I need to know an approach how to display these fields in a correct way.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 08:48:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-decode-netflow-elements-Key-Values-pair/m-p/446673#M54965</guid>
      <dc:creator>pkarpushin</dc:creator>
      <dc:date>2018-10-26T08:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to decode netflow_elements Key Values pair?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-decode-netflow-elements-Key-Values-pair/m-p/562714#M74899</link>
      <description>&lt;P&gt;Hi, did you manage to decode these values? I have the same problem with Cisco High Speed Logging.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 08:38:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-decode-netflow-elements-Key-Values-pair/m-p/562714#M74899</guid>
      <dc:creator>fox27374</dc:creator>
      <dc:date>2021-08-10T08:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to decode netflow_elements Key Values pair?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-decode-netflow-elements-Key-Values-pair/m-p/595201#M76693</link>
      <description>&lt;P&gt;I have a similar challenge - just a different source. Did anyone find an suitable approach?&lt;/P&gt;&lt;P&gt;netflow_elements: [ [-]&lt;BR /&gt;5951.638 : 0000&lt;BR /&gt;5951.352 : 0002&lt;BR /&gt;5951.353 : 2a91b70a&lt;BR /&gt;]&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 13:01:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-decode-netflow-elements-Key-Values-pair/m-p/595201#M76693</guid>
      <dc:creator>Stan816</dc:creator>
      <dc:date>2022-04-25T13:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to decode netflow_elements Key Values pair?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-decode-netflow-elements-Key-Values-pair/m-p/595345#M76710</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224718"&gt;@Stan816&lt;/a&gt;&amp;nbsp;-&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’m a Community Moderator in the Splunk Community. Thanks for contributing as a member in the forum!&lt;/P&gt;&lt;P&gt;This question was posted 4 years ago and might not get the attention you need for your own question to be answered. I suggest you please post a brand new question with proper details about the issue you are facing so your issue can get more visibility. To increase your chances of getting help from the community, follow&lt;I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunkbase/splunkbase/Answers/Questions?_gl=1*tm7cin*_ga*NTMzODg1OTQ4LjE2MzU3NTM5NzA.*_gid*NzIyMjU5ODM0LjE2NTAyNzg4NTE.&amp;amp;_ga=2.43557283.722259834.1650278851-533885948.1635753970" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;I&gt;&lt;SPAN&gt;these guidelines&lt;/SPAN&gt;&lt;/I&gt;&lt;/A&gt;&lt;I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;in the Splunk Answers User Manual when creating your post.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 06:46:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-decode-netflow-elements-Key-Values-pair/m-p/595345#M76710</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-04-26T06:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to decode netflow_elements Key Values pair?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-decode-netflow-elements-Key-Values-pair/m-p/631183#M78536</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/114768"&gt;@pkarpushin&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you find a solution to this issue? I am facing the exactly same issue in my environment. I tried following &lt;A title="Automatically input data with Netflow proprietary configurations" href="https://docs.splunk.com/Documentation/StreamApp/8.1.0/DeployStreamApp/AutoinputNetflow#Create_configuration_apps" target="_blank" rel="noopener"&gt;THIS&lt;/A&gt; Splunk doc, but it didn't work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if you have any leads on this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 12:38:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-decode-netflow-elements-Key-Values-pair/m-p/631183#M78536</guid>
      <dc:creator>dhruvilbhatt</dc:creator>
      <dc:date>2023-02-16T12:38:24Z</dc:date>
    </item>
  </channel>
</rss>

