I changed my configuration to use the index ipfix that sends the data to the splunk DB. After some time, data began to be interpreted but in the server error log the reported error with template 284 still shows the same issue.
index=_internal source=splunkd.log (log_level=ERROR OR log_level=CRIT OR log_level=FATAL) _raw="03-31-2015 13:12:14.610 -0400 ERROR ExecProcessor - message from \"python /opt/hunk/etc/apps/Splunk_TA_ipfix/bin/ipfix.py\" WARNING:root:Have not implemented parsing for 'None' of length 8 (5951:319) required for template 284."
Any idea of how I can get this template imported\available for virtual indexes?
... View more