- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

edwardrose
Contributor
07-24-2015
03:02 PM
Hello
Anyone seen this error before?
07-24-2015 14:57:17.658 -0700 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/Splunk_TA_ipfix/bin/ipfix.py" WARNING:root:Can't parse Data Set with Template ID: 258 (from DataSource(host='147.34.91.3', port=26741, observer=0)) with no template. Data: 0000000100000000000000001c32591b08f6fde51c32591b040600009322448d93225b0fe62901bb00000000000000010000000000000571180000000005022000d95d33450002e061d95d3348000f2cbd000000038000000300019b16010001000100010001000100
07-24-2015 14:57:17.658 -0700 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/Splunk_TA_ipfix/bin/ipfix.py" WARNING:root:Can't parse Data Set with Template ID: 257 (from DataSource(host='147.34.91.3', port=26741, observer=0)) with no template. Data: 0000000100000000000000001c32591c08f6fde51c32591b0406000093225b0f9322448d01bbe629000000000000000200000000000001a5180000000041002000d95d3345000f1d32d95d3348000f2cbd000018f6000000028000000300019b16
Any help would be appreciated.
Thanks
ed
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

jcoates_splunk

Splunk Employee
07-25-2015
10:15 AM
because it can't parse that data set. Have you loaded the appropriate template? http://docs.splunk.com/Documentation/AddOns/latest/IPFIX/ConfigureEnterpriseInformationElements
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

jcoates_splunk

Splunk Employee
07-25-2015
10:15 AM
because it can't parse that data set. Have you loaded the appropriate template? http://docs.splunk.com/Documentation/AddOns/latest/IPFIX/ConfigureEnterpriseInformationElements
