<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with NetFlow v9 Templates Not Received by Splunk Stream – Flows Being Dropped in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-NetFlow-v9-Templates-Not-Received-by-Splunk-Stream/m-p/748451#M241992</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/275296"&gt;@kn450&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk Stream requires NetFlow v9/IPFIX templates to be received before it can decode flow records; if templates arrive infrequently or are missed, flows are dropped.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm not aware of any specific known issues around this, but I certainly think it is worth&amp;nbsp;configuring Flowmon to send templates&amp;nbsp;&lt;STRONG&gt;much more frequently&lt;/STRONG&gt;&amp;nbsp;(ideally every 20–30 seconds, not just every 600 seconds or 4096 packets) and see if this alleviate the issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Sat, 21 Jun 2025 06:27:06 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-06-21T06:27:06Z</dc:date>
    <item>
      <title>Issue with NetFlow v9 Templates Not Received by Splunk Stream – Flows Being Dropped</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-NetFlow-v9-Templates-Not-Received-by-Splunk-Stream/m-p/748450#M241991</link>
      <description>&lt;P&gt;Hi Splunk Community,&lt;/P&gt;&lt;P&gt;I'm currently integrating Flowmon ndr as a NetFlow data exporter to Splunk Stream, but I’m encountering a persistent issue where Splunk receives the flow data, yet it’s not decoded properly, and flow sets are being dropped due to missing templates.&lt;/P&gt;&lt;P&gt;Here’s the warning from the Splunk log:&lt;/P&gt;&lt;P&gt;```&lt;BR /&gt;2025-06-21 08:34:49 WARN [139703701448448] (NetflowManager/NetflowDecoder.cpp:1282) stream.NetflowReceiver - NetFlowDecoder::decodeFlow Unable to decode flow set data. No template with id 258 received for observation domain id 13000 from device 10.x.x.x. Dropping flow data set of size 328&lt;BR /&gt;```&lt;/P&gt;&lt;P&gt;Setup details:&lt;/P&gt;&lt;P&gt;Exporter: Flowmon&lt;BR /&gt;Collector: Splunk Stream&lt;BR /&gt;&amp;nbsp;Protocol: NetFlow v9 (also tested with IPFIX)&lt;BR /&gt;Transport: UDP&lt;BR /&gt;&amp;nbsp;Template Resend Configuration: Every 4096 packets or&amp;nbsp; 600 seconds&lt;/P&gt;&lt;P&gt;Despite verifying these settings on Flowmon, Splunk continues to report that the template ID (in this case, 258) was never received, causing all related flows to be dropped.&lt;/P&gt;&lt;P&gt;My questions:&lt;/P&gt;&lt;P&gt;1. Has anyone successfully integrated Flowmon with Splunk Stream using NetFlow v9?&lt;BR /&gt;2. Is there a known issue with Splunk Stream not handling templates properly from certain exporters?&lt;BR /&gt;3. Are there any recommended Splunk Stream configuration tweaks for handling late or infrequent templates?&lt;/P&gt;&lt;P&gt;Any insights, experiences, or troubleshooting tips would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jun 2025 06:20:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-with-NetFlow-v9-Templates-Not-Received-by-Splunk-Stream/m-p/748450#M241991</guid>
      <dc:creator>kn450</dc:creator>
      <dc:date>2025-06-21T06:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with NetFlow v9 Templates Not Received by Splunk Stream – Flows Being Dropped</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-NetFlow-v9-Templates-Not-Received-by-Splunk-Stream/m-p/748451#M241992</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/275296"&gt;@kn450&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk Stream requires NetFlow v9/IPFIX templates to be received before it can decode flow records; if templates arrive infrequently or are missed, flows are dropped.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm not aware of any specific known issues around this, but I certainly think it is worth&amp;nbsp;configuring Flowmon to send templates&amp;nbsp;&lt;STRONG&gt;much more frequently&lt;/STRONG&gt;&amp;nbsp;(ideally every 20–30 seconds, not just every 600 seconds or 4096 packets) and see if this alleviate the issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jun 2025 06:27:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-with-NetFlow-v9-Templates-Not-Received-by-Splunk-Stream/m-p/748451#M241992</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-21T06:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with NetFlow v9 Templates Not Received by Splunk Stream – Flows Being Dropped</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-NetFlow-v9-Templates-Not-Received-by-Splunk-Stream/m-p/748452#M241993</link>
      <description>&lt;P&gt;I changed the time and the pack size, but the problem still exists.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jun 2025 06:53:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-with-NetFlow-v9-Templates-Not-Received-by-Splunk-Stream/m-p/748452#M241993</guid>
      <dc:creator>kn450</dc:creator>
      <dc:date>2025-06-21T06:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with NetFlow v9 Templates Not Received by Splunk Stream – Flows Being Dropped</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-NetFlow-v9-Templates-Not-Received-by-Splunk-Stream/m-p/749633#M242193</link>
      <description>&lt;P&gt;There currently is an issue with NF 9 and STREAM 8.1.5.&lt;BR /&gt;I suggest downgrading until there's a newer release.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 14:51:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-with-NetFlow-v9-Templates-Not-Received-by-Splunk-Stream/m-p/749633#M242193</guid>
      <dc:creator>uthornander_spl</dc:creator>
      <dc:date>2025-07-11T14:51:03Z</dc:date>
    </item>
  </channel>
</rss>

