<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Flow Sensor - ERSPAN in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/flow-sensor-erspan/m-p/5218037#M1111</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I am testing SNA (Stealthwatch) in my lab (ESXi). I have installed version 7.5.1 - SMC, Flow Collector, Flow Sensor, Data Store.&lt;/P&gt;
&lt;P&gt;I want to test Flow sensor. I have added additional interface for SPAN traffic. I have enabled "ERSPAN Decapsulation".&lt;/P&gt;
&lt;P&gt;On Nexus&amp;nbsp;93180yc I have configured ERSPAN:&lt;/P&gt;
&lt;P&gt;monitor session 3 type erspan-source&lt;BR /&gt;description StealthWatch&lt;BR /&gt;erspan-id 1&lt;BR /&gt;vrf default&lt;BR /&gt;destination ip x.x.x.x&lt;BR /&gt;source vlan 333 both&lt;BR /&gt;no shut&lt;/P&gt;
&lt;P&gt;monitor erspan origin ip-address y.y.y.y global&lt;/P&gt;
&lt;P&gt;I am able to see gre packets on flow sensor when using packet capture.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="llomjaria_0-1730377510758.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/232824iAE79BA946134CE51/image-size/medium?v=v2&amp;amp;px=400" role="button" title="llomjaria_0-1730377510758.png" alt="llomjaria_0-1730377510758.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But I do not see anything when trying to search flows on SMC.&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;</description>
    <pubDate>Thu, 31 Oct 2024 12:26:30 GMT</pubDate>
    <dc:creator>llomjaria</dc:creator>
    <dc:date>2024-10-31T12:26:30Z</dc:date>
    <item>
      <title>Flow Sensor - ERSPAN</title>
      <link>https://community.cisco.com/t5/security-analytics/flow-sensor-erspan/m-p/5218037#M1111</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I am testing SNA (Stealthwatch) in my lab (ESXi). I have installed version 7.5.1 - SMC, Flow Collector, Flow Sensor, Data Store.&lt;/P&gt;
&lt;P&gt;I want to test Flow sensor. I have added additional interface for SPAN traffic. I have enabled "ERSPAN Decapsulation".&lt;/P&gt;
&lt;P&gt;On Nexus&amp;nbsp;93180yc I have configured ERSPAN:&lt;/P&gt;
&lt;P&gt;monitor session 3 type erspan-source&lt;BR /&gt;description StealthWatch&lt;BR /&gt;erspan-id 1&lt;BR /&gt;vrf default&lt;BR /&gt;destination ip x.x.x.x&lt;BR /&gt;source vlan 333 both&lt;BR /&gt;no shut&lt;/P&gt;
&lt;P&gt;monitor erspan origin ip-address y.y.y.y global&lt;/P&gt;
&lt;P&gt;I am able to see gre packets on flow sensor when using packet capture.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="llomjaria_0-1730377510758.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/232824iAE79BA946134CE51/image-size/medium?v=v2&amp;amp;px=400" role="button" title="llomjaria_0-1730377510758.png" alt="llomjaria_0-1730377510758.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But I do not see anything when trying to search flows on SMC.&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 12:26:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/flow-sensor-erspan/m-p/5218037#M1111</guid>
      <dc:creator>llomjaria</dc:creator>
      <dc:date>2024-10-31T12:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Flow Sensor - ERSPAN</title>
      <link>https://community.cisco.com/t5/security-analytics/flow-sensor-erspan/m-p/5218080#M1112</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Have you configured ERSPAN on the FlowSensor?&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-analytics/stealthwatch-7-3-erspan/td-p/4178516" target="_blank"&gt;https://community.cisco.com/t5/security-analytics/stealthwatch-7-3-erspan/td-p/4178516&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 13:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/flow-sensor-erspan/m-p/5218080#M1112</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2024-10-31T13:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: Flow Sensor - ERSPAN</title>
      <link>https://community.cisco.com/t5/security-analytics/flow-sensor-erspan/m-p/5218115#M1113</link>
      <description>&lt;P&gt;Yes, I have enabled ERSPAN decapsulation and added interface on Flow Sensor&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 13:57:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/flow-sensor-erspan/m-p/5218115#M1113</guid>
      <dc:creator>llomjaria</dc:creator>
      <dc:date>2024-10-31T13:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: Flow Sensor - ERSPAN</title>
      <link>https://community.cisco.com/t5/security-analytics/flow-sensor-erspan/m-p/5218185#M1114</link>
      <description>&lt;P&gt;Most basic question first: is there traffic being sent through the interfaces you are ERSPAN’ing to the Flow Sensor? In your screenshot all the packets have the same length and they’re not coming very fast. Lets make sure the encapsulated SPAN packets are not just empty boxcars before worrying further (:&lt;BR /&gt;&lt;BR /&gt;For future reference the configuration on the Flow Sensor for ERSPAN has gotten a lot easier, it’s just a check-box now … here’s a link to the current configuration guide with the steps to enable it. Do not miss the “reboot the flow sensor” step at the end ...&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/system_installation_configuration/7_5_1_System_Configuration_Guide_DV_1_2.pdf#%5B%7B%22num%22%3A398%2C%22gen%22%3A0%7D%2C%7B%22name%22%3A%22XYZ%22%7D%2C72%2C648.75%2C0%5D" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/system_installation_configuration/7_5_1_System_Configuration_Guide_DV_1_2.pdf#%5B%7B%22num%22%3A398%2C%22gen%22%3A0%7D%2C%7B%22name%22%3A%22XYZ%22%7D%2C72%2C648.75%2C0%5D&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If that’s working, the next thing to check is the Engine Status table on the front page of the Flow Sensor appliance. You should see data in the Capture columns confirming that you’re getting the SPAN traffic in. The drops should be low and will reset at reboot. Process and Export columns should show that you are sending data out to the Flow Collector destination you have configured.&lt;BR /&gt;&lt;BR /&gt;If this is working you can move to checking the Flow Collector for input from this exporter. I would probably get into the SNA Report builder interface to look.&lt;BR /&gt;&lt;BR /&gt;If this is not working, go back to the configuration guide linked above and make sure the FS and ERSPAN configurations are correct.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Here’s an example from mine where the thing is working correctly… (I do not believe I had ERSPAN configured in this case)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jamegill_0-1730389101880.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/232837iC3E83CBFA7DB52CF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jamegill_0-1730389101880.png" alt="jamegill_0-1730389101880.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 15:38:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/flow-sensor-erspan/m-p/5218185#M1114</guid>
      <dc:creator>jamegill</dc:creator>
      <dc:date>2024-10-31T15:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Flow Sensor - ERSPAN</title>
      <link>https://community.cisco.com/t5/security-analytics/flow-sensor-erspan/m-p/5247434#M1124</link>
      <description>&lt;P&gt;I had issues with ERSPAN in my lab, too. The trick at my lab was, that the ERSPAN interface of FlowSensor and the Mgt Interface if FlowSenor must be in seperate VLANs! Check that&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 11:42:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/flow-sensor-erspan/m-p/5247434#M1124</guid>
      <dc:creator>andre.baumgarten</dc:creator>
      <dc:date>2025-01-15T11:42:45Z</dc:date>
    </item>
  </channel>
</rss>

