Hello Everyone
I have a problem with receiving IPFIX flow From NSX-T 3.1.
this is a summary of what I do:
I checked Firewall things and it doesn't have any problem because I can see IPFIX flow with Wireshark on the Splunk server.
I use Splunk_TA_stream and splunk_app_stream 8.0.1 and I can Get IPFix flow with IPFIX Generator( flowalyzer).
I change the Splunk Stream configuration for those IPFIX fields that NSX-T sends. because some of IPFIX is not Standard.
I changed the Splunk Stream configuration based on these Link according to this Link:
https://emc.extremenetworks.com/content/oneview/docs/analytics/docs/pur_splunk.htm?Highlight=Splunk
https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.0/nsxt_30_admin.pdf
Does anybody have experience in Receiving IPFIX flow from NSX-T?