<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: netflow missing fields problem with flowIntegrator in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/netflow-missing-fields-problem-with-flowIntegrator/m-p/63861#M12844</link>
    <description>&lt;P&gt;The field for destination_addr is supported in another rule available in the latest beta for 2.0. You will need to register for it on our website: &lt;A href="http://www.netflowlogic.com"&gt;http://www.netflowlogic.com&lt;/A&gt;. If you have any additional questions or support requests, please see our support site at: &lt;A href="https://netflowlogic.zendesk.com/home"&gt;https://netflowlogic.zendesk.com/home&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Jan 2013 00:27:18 GMT</pubDate>
    <dc:creator>dmiller2010</dc:creator>
    <dc:date>2013-01-16T00:27:18Z</dc:date>
    <item>
      <title>netflow missing fields problem with flowIntegrator</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/netflow-missing-fields-problem-with-flowIntegrator/m-p/63860#M12843</link>
      <description>&lt;P&gt;Hi all, &lt;/P&gt;

&lt;P&gt;I managed to retrieve netflow from my cisco firewall by using flowIntegrator and splunk. But the problem is : The netflow record that I get have missing fields like destination_addr. I copied the netflow data with key-value match that I retrieved below. Is there anyone have any idea about this issue? Any help is appreciated.&lt;/P&gt;

&lt;P&gt;_sourcetype:  flowintegrator&lt;BR /&gt;&lt;BR /&gt;
index:  main&lt;BR /&gt;&lt;BR /&gt;
t_int:  30005&lt;BR /&gt;&lt;BR /&gt;
bytes:  0&lt;BR /&gt;&lt;BR /&gt;
host:  127.0.0.1&lt;BR /&gt;&lt;BR /&gt;
   _cd:  1:63560&lt;BR /&gt;&lt;BR /&gt;
   _serial:  0&lt;BR /&gt;&lt;BR /&gt;
   fi_module:  50015&lt;BR /&gt;&lt;BR /&gt;
   _si:  ubuntu,main&lt;BR /&gt;&lt;BR /&gt;
   date:  Dec 13 11:49:23&lt;BR /&gt;&lt;BR /&gt;
   splunk_server:  ubuntu&lt;BR /&gt;&lt;BR /&gt;
   linecount:  1&lt;BR /&gt;&lt;BR /&gt;
   percent_of_total:  0&lt;BR /&gt;&lt;BR /&gt;
   _indextime:  1355392163&lt;BR /&gt;&lt;BR /&gt;
   denied_cnt:  1&lt;BR /&gt;&lt;BR /&gt;
   username:  na&lt;BR /&gt;&lt;BR /&gt;
   created_cnt:  1&lt;BR /&gt;&lt;BR /&gt;
   source:  netflow&lt;BR /&gt;&lt;BR /&gt;
   sourcetype:  flowintegrator&lt;BR /&gt;&lt;BR /&gt;
   _bkt:  main~1~3984975D-B674-425B-B482-EA9629744985&lt;BR /&gt;&lt;BR /&gt;
   _time:  2012-12-13T11:49:23.000+02:00&lt;BR /&gt;&lt;BR /&gt;
   ipv4_src_addr:  31.13.72.7&lt;BR /&gt;&lt;BR /&gt;
   _raw:  Dec 13 11:49:23 ff:ff:00:01 fi_module=50015 ipv4_src_addr=31.13.72.7 username=na created_cnt=1 denied_cnt=1 bytes=0 percent_of_total=0 t_int=30005   &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:58:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/netflow-missing-fields-problem-with-flowIntegrator/m-p/63860#M12843</guid>
      <dc:creator>yunusemreakbaba</dc:creator>
      <dc:date>2020-09-28T12:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: netflow missing fields problem with flowIntegrator</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/netflow-missing-fields-problem-with-flowIntegrator/m-p/63861#M12844</link>
      <description>&lt;P&gt;The field for destination_addr is supported in another rule available in the latest beta for 2.0. You will need to register for it on our website: &lt;A href="http://www.netflowlogic.com"&gt;http://www.netflowlogic.com&lt;/A&gt;. If you have any additional questions or support requests, please see our support site at: &lt;A href="https://netflowlogic.zendesk.com/home"&gt;https://netflowlogic.zendesk.com/home&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2013 00:27:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/netflow-missing-fields-problem-with-flowIntegrator/m-p/63861#M12844</guid>
      <dc:creator>dmiller2010</dc:creator>
      <dc:date>2013-01-16T00:27:18Z</dc:date>
    </item>
  </channel>
</rss>

