<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPFIX Add-On failing when using Virtual Indexer in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110974#M8041</link>
    <description>&lt;P&gt;Getting same error although we are seeing ipfix data. Is there any update on this? We are not using Hunk.&lt;/P&gt;</description>
    <pubDate>Fri, 13 May 2016 13:30:56 GMT</pubDate>
    <dc:creator>ejenson_splunk</dc:creator>
    <dc:date>2016-05-13T13:30:56Z</dc:date>
    <item>
      <title>IPFIX Add-On failing when using Virtual Indexer</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110966#M8033</link>
      <description>&lt;P&gt;Have IPFIX setup successfully with a Virtual Index on my Hadoop Cluster but it keeps erroring with the below message. This has been running over 4 hours. Can someone help me?&lt;/P&gt;

&lt;P&gt;index=_internal source=&lt;EM&gt;splunkd.log&lt;/EM&gt; (log_level=ERROR OR log_level=CRIT OR log_level=FATAL) _raw="03-27-2015 17:02:46.438 -0400 ERROR ExecProcessor - message from \"python /opt/hunk/etc/apps/Splunk_TA_ipfix/bin/ipfix.py\" WARNING:root:Have not implemented parsing for 'None' of length 8 (5951:319) required for template 284." source="/opt/hunk/var/log/splunk/splunkd.log"&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110966#M8033</guid>
      <dc:creator>mbharrel</dc:creator>
      <dc:date>2020-09-28T19:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPFIX Add-On failing when using Virtual Indexer</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110967#M8034</link>
      <description>&lt;P&gt;what version of IPFIX?&lt;/P&gt;</description>
      <pubDate>Sat, 28 Mar 2015 00:07:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110967#M8034</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-03-28T00:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: IPFIX Add-On failing when using Virtual Indexer</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110968#M8035</link>
      <description>&lt;P&gt;I am running the below. Is there an update or patch that I am missing?&lt;/P&gt;

&lt;P&gt;Splunk Version 6.2.1&lt;BR /&gt;
Splunk Build 249325&lt;/P&gt;

&lt;P&gt;Splunk Add-on for IPFIX&lt;BR /&gt;
App Version 5.0.3&lt;/P&gt;</description>
      <pubDate>Sat, 28 Mar 2015 02:32:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110968#M8035</guid>
      <dc:creator>mbharrel</dc:creator>
      <dc:date>2015-03-28T02:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: IPFIX Add-On failing when using Virtual Indexer</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110969#M8036</link>
      <description>&lt;P&gt;hey, nope, I was just making sure... we don't test IPFIX with Hunk, so it might be related to that, but I wanted to make sure it wasn't something that we already knew about. This looks like it could be a screwy template... we accept a template from the device to instruct us on parsing, and this might mean that it's not lining up with the data. If you can check with a Splunk Enterprise instance too and verify that it acts the same there, this would be worth a support ticket, some more detail, and a pcap if you can.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Mar 2015 02:48:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110969#M8036</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-03-28T02:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPFIX Add-On failing when using Virtual Indexer</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110970#M8037</link>
      <description>&lt;P&gt;Do you mean to test with a native index? &lt;/P&gt;</description>
      <pubDate>Sat, 28 Mar 2015 02:58:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110970#M8037</guid>
      <dc:creator>mbharrel</dc:creator>
      <dc:date>2015-03-28T02:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: IPFIX Add-On failing when using Virtual Indexer</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110971#M8038</link>
      <description>&lt;P&gt;Yeah, I doubt if it would work differently, but might as well limit the differences between supported config and real world.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Mar 2015 23:59:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110971#M8038</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-03-28T23:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: IPFIX Add-On failing when using Virtual Indexer</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110972#M8039</link>
      <description>&lt;P&gt;I will test it but is ipfix not a supported add-on for Hunk? How else are users supposed to get ipfix data into HDFS?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Mar 2015 01:14:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110972#M8039</guid>
      <dc:creator>mbharrel</dc:creator>
      <dc:date>2015-03-29T01:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: IPFIX Add-On failing when using Virtual Indexer</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110973#M8040</link>
      <description>&lt;P&gt;I changed my configuration to use the index ipfix that sends the data to the splunk DB. After some time, data began to be interpreted but in the server error log the reported error with template 284 still shows the same issue.&lt;/P&gt;

&lt;P&gt;index=_internal source=&lt;EM&gt;splunkd.log&lt;/EM&gt; (log_level=ERROR OR log_level=CRIT OR log_level=FATAL) _raw="03-31-2015 13:12:14.610 -0400 ERROR ExecProcessor - message from \"python /opt/hunk/etc/apps/Splunk_TA_ipfix/bin/ipfix.py\" WARNING:root:Have not implemented parsing for 'None' of length 8 (5951:319) required for template 284."&lt;/P&gt;

&lt;P&gt;Any idea of how I can get this template imported\available for virtual indexes?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:21:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110973#M8040</guid>
      <dc:creator>mbharrel</dc:creator>
      <dc:date>2020-09-28T19:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: IPFIX Add-On failing when using Virtual Indexer</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110974#M8041</link>
      <description>&lt;P&gt;Getting same error although we are seeing ipfix data. Is there any update on this? We are not using Hunk.&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 13:30:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/IPFIX-Add-On-failing-when-using-Virtual-Indexer/m-p/110974#M8041</guid>
      <dc:creator>ejenson_splunk</dc:creator>
      <dc:date>2016-05-13T13:30:56Z</dc:date>
    </item>
  </channel>
</rss>

