Hello Cisco Community,
we have a little problem in our company with sending netflow data from the Cisco Prime NAMs to Stealtwatch. There is any documentation for this topic, but we thought that it should be possible to use the NAMs as exporters for Stealthwatch. So, we made the export configuration for the NAM and we are now able to see it as an exporter in Stealtwatch, but we are not able to see any flows from this exporter. We’ve tried to watch the exported information in Wireshark and there are the expected data showed.
Did anybody try this type of export too? Is it actually possible to use the NAMs as exporters for Stealthwatch?
We really tried anything, but we couldn’t make this work..
please refer to page 16 on this guide: https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/netflow/config-trouble-netflow-stealth.pdf to make sure the minimum requirements are met. Don't have a NAM at hand, but if minimum requirements are met and the FC is licensed, the flows should come up.
We already use the FC to collect data from other exporters as swithces, firewalls or routers and it works very well.
But to configure the NAM there are only few settings which can be done. Enclosed is a screenshot with the NAM configuration.
Yes, we already tried all the possible combinations, but nothing works. I also think that the problem is with the exported format from the NAM. Do you know if there is another way to configure the NAM as netflow exporter, so that we can choose the right template for the SW FC? Or are there any specialists for the NAMs which we could ask?