All Apps and Add-ons

How can I receive ipfix from YAF (Yet Another Flowmeter)?

banaie
Path Finder

Hi all,
I was trying to receive ipfix from YAF (Yet Another Flowmeter). I changed the yaf config to udp and I thought I would receive events perfectly. But, YAF says in the log file that the connection is refused! However, I have defined the datainput to receive IPFIX on the default 4739 port and it is listening perfectly.

Please help me on this.

Thanks a lot

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee
0 Karma

banaie
Path Finder

I managed to solve the problem by inputting the server ip instead of localhost on the yaf config. However, I can't receive application labels and other deep packet information on the index.
Is there any approach for receiving all the information that yaf can provide?

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...