I have a problem with receiving IPFIX flow From NSX-T 3.1.
this is a summary of what I do:
I checked Firewall things and it doesn't have any problem because I can see IPFIX flow with Wireshark on the Splunk server.
I use Splunk_TA_stream and splunk_app_stream 8.0.1 and I can Get IPFix flow with IPFIX Generator( flowalyzer).
I change the Splunk Stream configuration for those IPFIX fields that NSX-T sends. because some of IPFIX is not Standard.
I changed the Splunk Stream configuration based on these Link according to this Link:
Does anybody have experience in Receiving IPFIX flow from NSX-T?