<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Streamfwd drops IPFIX data with “no template received”—pcap shows templates arrive after data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Streamfwd-drops-IPFIX-data-with-no-template-received-pcap-shows/m-p/752803#M119510</link>
    <description>&lt;P&gt;Environment&lt;BR /&gt;- Splunk Enterprise 10.0.0 (Ubuntu 24.04), single VM (indexer+SH+Stream)&lt;BR /&gt;- splunk_app_stream 8.1.5, Splunk_TA_stream 8.1.5&lt;BR /&gt;- Exporter: NetQuest SNS, IPFIX on UDP/2055, templates 258/259/550&lt;BR /&gt;- streamfwd.conf:&lt;BR /&gt;[streamfwd]&lt;BR /&gt;netflowReceiver.0.decoder = netflow&lt;BR /&gt;netflowReceiver.0.port = 2055&lt;BR /&gt;- inputs.conf:&lt;BR /&gt;[streamfwd://streamfwd]&lt;BR /&gt;splunk_stream_app_location = &lt;A href="https://localhost:8000/en-us/custom/splunk_app_stream/" target="_blank" rel="noopener"&gt;https://localhost:8000/en-us/custom/splunk_app_stream/&lt;/A&gt;&lt;BR /&gt;disabled = 0&lt;/P&gt;&lt;P&gt;Symptoms&lt;BR /&gt;- streamfwd.log: “Unable to decode flow set data. No template with id 258/550 received …”&lt;BR /&gt;- splunkd.log has Web/401/CSRF noise, but data path is working (streamfwd bound on 2055, tcpdump shows traffic).&lt;BR /&gt;- Wireshark confirms templates are present, but shows lines like:&lt;BR /&gt;“Template Frame: NNN (received after this frame)”&lt;BR /&gt;when inspecting Data Sets with Set ID 258/550.&lt;/P&gt;&lt;P&gt;Question&lt;BR /&gt;- Does Streamfwd strictly require that Template Sets for a given observationDomainId be received *before* any Data Sets? If so, is there a setting to buffer or accept out-of-order templates?&lt;BR /&gt;- Any known best practices for exporters that may send Data Sets immediately on start, before a template refresh?&lt;BR /&gt;- If the exporter uses enterprise/private fields in those templates, do we need a custom mapping for Stream to parse them?&lt;/P&gt;&lt;P&gt;What I’ve tried&lt;BR /&gt;- Confirmed the doc’d minimal config and enabled the “netflow” metadata stream.&lt;BR /&gt;- Verified with tcpdump/pcap that the SNS sends templates every minute and option templates (ID 550) every 30 seconds.&lt;BR /&gt;- Still seeing drops whenever a Data Set arrives before the matching template is cached.&lt;/P&gt;&lt;P&gt;Any guidance (config knobs in Stream, or exporter-side recommendations) would be appreciated.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Sep 2025 14:52:51 GMT</pubDate>
    <dc:creator>gsiebert</dc:creator>
    <dc:date>2025-09-08T14:52:51Z</dc:date>
    <item>
      <title>Streamfwd drops IPFIX data with “no template received”—pcap shows templates arrive after data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Streamfwd-drops-IPFIX-data-with-no-template-received-pcap-shows/m-p/752803#M119510</link>
      <description>&lt;P&gt;Environment&lt;BR /&gt;- Splunk Enterprise 10.0.0 (Ubuntu 24.04), single VM (indexer+SH+Stream)&lt;BR /&gt;- splunk_app_stream 8.1.5, Splunk_TA_stream 8.1.5&lt;BR /&gt;- Exporter: NetQuest SNS, IPFIX on UDP/2055, templates 258/259/550&lt;BR /&gt;- streamfwd.conf:&lt;BR /&gt;[streamfwd]&lt;BR /&gt;netflowReceiver.0.decoder = netflow&lt;BR /&gt;netflowReceiver.0.port = 2055&lt;BR /&gt;- inputs.conf:&lt;BR /&gt;[streamfwd://streamfwd]&lt;BR /&gt;splunk_stream_app_location = &lt;A href="https://localhost:8000/en-us/custom/splunk_app_stream/" target="_blank" rel="noopener"&gt;https://localhost:8000/en-us/custom/splunk_app_stream/&lt;/A&gt;&lt;BR /&gt;disabled = 0&lt;/P&gt;&lt;P&gt;Symptoms&lt;BR /&gt;- streamfwd.log: “Unable to decode flow set data. No template with id 258/550 received …”&lt;BR /&gt;- splunkd.log has Web/401/CSRF noise, but data path is working (streamfwd bound on 2055, tcpdump shows traffic).&lt;BR /&gt;- Wireshark confirms templates are present, but shows lines like:&lt;BR /&gt;“Template Frame: NNN (received after this frame)”&lt;BR /&gt;when inspecting Data Sets with Set ID 258/550.&lt;/P&gt;&lt;P&gt;Question&lt;BR /&gt;- Does Streamfwd strictly require that Template Sets for a given observationDomainId be received *before* any Data Sets? If so, is there a setting to buffer or accept out-of-order templates?&lt;BR /&gt;- Any known best practices for exporters that may send Data Sets immediately on start, before a template refresh?&lt;BR /&gt;- If the exporter uses enterprise/private fields in those templates, do we need a custom mapping for Stream to parse them?&lt;/P&gt;&lt;P&gt;What I’ve tried&lt;BR /&gt;- Confirmed the doc’d minimal config and enabled the “netflow” metadata stream.&lt;BR /&gt;- Verified with tcpdump/pcap that the SNS sends templates every minute and option templates (ID 550) every 30 seconds.&lt;BR /&gt;- Still seeing drops whenever a Data Set arrives before the matching template is cached.&lt;/P&gt;&lt;P&gt;Any guidance (config knobs in Stream, or exporter-side recommendations) would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 14:52:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Streamfwd-drops-IPFIX-data-with-no-template-received-pcap-shows/m-p/752803#M119510</guid>
      <dc:creator>gsiebert</dc:creator>
      <dc:date>2025-09-08T14:52:51Z</dc:date>
    </item>
  </channel>
</rss>

