Forum,
I am in the process of bringing a few 3850 switches into Netflow.
I have configured the flow record, the flow exporter, and the flow monitor.
On one specific switch, i have it configured to use vlan 1 as the source since it does not have a loopback configured on it.
When i run wireshark on the Solarwinds server (netflow collector in our example) and set capture filters for that host and for udp 2055, i see a "CFLOW" frame come in once every few seconds.
A technical call for a support ticket with Solarwinds Tier 2 indicated that there must be something incorrect within my configuration.
I have used the guide published here https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/netflow/Cisco_NetFlow_Configuration.pdf
and have specifically referenced the section which references the Catalyst 3850.
I am being told by Solarwinds that we should see many more flows than the ones i am seeing..
I