Closed thezoggy closed 4 months ago
Could you please send me by email one single nfcapd file, which reports this error and if possible a cap of the stream sent to the collector. I will check it.
The record is now known to the filter thread and is fixed in the master branch. It has however, no influence of the record processing and all output is correct.
updated and confirm I do not see the skip unknown records anymore, thanks!
Running version:
When looking at some traffic today I saw
Skip unknown record: #### type 13
showing up. I found your previous github issue talking https://github.com/phaag/nfdump/issues/503 about this being due to firewall device doing an export, which none of the devices that send netflow to this box are.Router is a cisco asr9k running exr 7.1.3
example:
Looking I see this shows up in each time bucket, and actual query string does not matter:
looking at latest bucket, and looking at those specific records to try and provide some details (masking some ips for anonymity)
checking some other cisco 7.1.3 devices, seeing
just looking around, not seeing these show up on nokia or juniper devices..
took pcap on another device and found one of these flows, screenshot from wireshark