05-29-2018 09:49 PM - edited 03-08-2019 03:10 PM
I am using Cisco ASR 1K .
I am trying to find how to export "flow.sampling_interval" value to collector in ELK.
please help.
05-30-2018 12:56 AM
Hello,
on the ASR, I think you need to configure Netflow version 8, which has the sample interval field in the header.
--> ip flow-export version 8
The corresponding field in your elastiflow config would be:
"[netflow][sampling_interval]" => "[flow][sampling_interval]"
05-30-2018 02:13 AM
05-30-2018 04:29 AM
Hello,
you have to configure an aggregation cache. Th examples below are an excerpt from the document linked...
configure terminal
!
ip flow-aggregation cache as
export destination 10.42.42.2 9991
export destination 10.42.41.1 9991
export version 8
enabled
!
interface Fastethernet0/0/0
ip flow ingress
configure terminal
!
ip flow-aggregation cache source-prefix
mask source minimum 30
enabled
!
interface Fastethernet0/0/0
ip flow ingress
!
end
05-30-2018 07:07 PM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: