Hi,
I'm not able to get a correct timestamps on my netflow v9 exported from my Cisco ASA.
Does anyone have a fixup ?
Thanks.
Cisco ASA support is coming in future versions of the NetFlow Integrator. It is a streaming technology that converts NetFlow to syslog, thus making it available in Splunk in real time. Sign up for Beta now. Demo App is here:
http://splunk-base.splunk.com/apps/NetFlow-based+Network+Monitoring+(Beta)
I was having the same issue. After some searching I found that the nfdump doesn't fully support Cisco ASAs in the current stable branches. The only branch that supports ASAs is the NSEL branch. See the sourceforge page here: http://sourceforge.net/projects/nfdump/. "For CISCO ASA devices, which export Netflow Security Event Loging (NSEL) records, please use nfdump-1.5.8-2-NSEL."
Cisco ASA support by the NetFlow Integrator is coming in two weeks. Please contact us if you are interested.