12-09-2019 03:47 AM
Hello Cisco Community,
we have a little problem in our company with sending netflow data from the Cisco Prime NAMs to Stealtwatch. There is any documentation for this topic, but we thought that it should be possible to use the NAMs as exporters for Stealthwatch. So, we made the export configuration for the NAM and we are now able to see it as an exporter in Stealtwatch, but we are not able to see any flows from this exporter. We’ve tried to watch the exported information in Wireshark and there are the expected data showed.
Did anybody try this type of export too? Is it actually possible to use the NAMs as exporters for Stealthwatch?
We really tried anything, but we couldn’t make this work..
12-09-2019 03:57 AM
Hello,
please refer to page 16 on this guide: https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/netflow/config-trouble-netflow-stealth.pdf to make sure the minimum requirements are met. Don't have a NAM at hand, but if minimum requirements are met and the FC is licensed, the flows should come up.
Dario
12-09-2019 06:52 AM
12-10-2019 10:03 AM
12-11-2019 01:25 AM
Yes, we already tried all the possible combinations, but nothing works. I also think that the problem is with the exported format from the NAM. Do you know if there is another way to configure the NAM as netflow exporter, so that we can choose the right template for the SW FC? Or are there any specialists for the NAMs which we could ask?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide