repeatedly / fluent-plugin-netflow

Netflow plugin for Fluentd
59 stars 24 forks source link

No matching template for host="x.x.x.x" source_id=0 flowset_id=1315 #41

Open GerryLon opened 5 years ago

GerryLon commented 5 years ago

My env: fluent-plugin-netflow version: 1.0.2 Netflow device: Huawei AR2204-S(possible netstream) pcap file sent to your mail box.

Many Thanks!

repeatedly commented 5 years ago

I'm not familiar with Huawei AR2204-S. Your device seems to send original format logs. You need to define your template for it. Here is an example:

https://github.com/repeatedly/fluent-plugin-netflow#field-definition-for-netflow-v9 https://github.com/repeatedly/fluent-plugin-netflow#paloalto-netflow