repeatedly/fluent-plugin-netflow

Support for devices using VarString in Netflow v9 like H3C Netstream

Opened this issue · 1 comments

Hi all. I tried to use Fluentd to collect h3c netflow v9 messages but the following errors are reported:

Template length doesn't fit cleanly into flowset template_id=3281 template_length=65615 flowset_length=84

Packet captures are attached here:
http://p3s9jxyns.bkt.clouddn.com/tmp/h3c-netstream.cap

Could you kindly add support for this?
Thank you very much!

I'm not familiar with h3c netflow but you can add additional patterns by definitions parameter. See this thread for example: #27