Closed keegoid-nr closed 10 months ago
I think this looks good to me. @tma-tik -- can you confirm? Thanks!
Kentik has some config snippits at https://github.com/kentik/config-snippets but I don't see an explicit 9500 series one there.
it looks good but to truly confirm that, is to actually configure it on the actual device, which we don't have.
however, we are using
the catalyst cat8k and cat9k series runs on IOS-XE 17.x, i think it should be fine.
This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days.
This issue was closed because it has been stalled for 5 days with no activity.
Confirming the following flow records are correct to send to New Relic from Cisco Catalyst 9300 and 9500 switches. Some data is arriving, some is not.
Prior to adding the above flow records, the following attributes were showing up in New Relic (missing source/destination IPs and bytes metrics fields):
Do you see any issues with the following general steps?
Create a Flow Record: In this example, we will create a flow record named "NewRelicFlowRecord" that includes the following fields:
The configuration command for creating the flow record would be:
Configure the Cisco Catalyst 9300 and 9500 switches: Follow the appropriate Cisco documentation[1][4] to configure the switches according to your network requirements.
Configure the IPFIX Exporter: Set up the IPFIX exporter on your Cisco Catalyst switches to send flow records to the New Relic collector. Specify the IP address of the New Relic collector and the interface to send the flows from. In this example, we will use interface GigabitEthernet1/0/48 as the source interface. The configuration command for the IPFIX exporter would be:
Apply Flow Monitor to Interfaces: After combining the flow record and exporter values into a flow monitor, you can apply the flow monitor to the desired interfaces. Specify the direction (input or output) and the interfaces to monitor. In this example, we will apply the flow monitor to the input direction of interface GigabitEthernet1/0/1. The configuration command would be:
Configure New Relic to receive IPFIX data: Follow the New Relic documentation[2] to set up the necessary configurations for receiving IPFIX data from the Cisco Catalyst switches.
Visualize network traffic flows: Once the configurations are in place, you can use New Relic One Network Monitoring to visualize network traffic flows and track network infrastructure metrics alongside other telemetry data[6].
Please note that the above example is a general guide, and the specific configuration commands may vary depending on your network setup and requirements. Always refer to the official documentation for your specific switch model and software version.
References:
Citations: [1] https://www.examtopics.com/discussions/cisco/view/74413-exam-350-701-topic-1-question-141-discussion/ [2] https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/netflow/Cisco_NetFlow_Configuration.pdf [3] https://www.noction.com/blog/cisco-catalyst-netflow-configuration [4] https://www.plixer.com/blog/cisco-catalyst-9300-netflow-configuration/ [5] https://developers.cloudflare.com/magic-network-monitoring/routers/netflow-ipfix-config/ [6] https://forum.newrelic.com/ForumsRedirectPage?old_topic=155875