I'm seeing this error lines when received IPFIX messages and no data shown as well.
NetFlow (v9) seems working fine. What could be possibly wrong here?
INFO netflow_utils:228 - No matching ipfix app found, terminating the process of pulling configuration from vendor app...
= below are the version info =
Splunk Stream 8.1.0
Splunk_TA_stream_wire_data 8.1.0
Splunk_TA_stream 8.1.0
Splunk Enterprise
Version: 9.0.4 Build: de405f4a7979 Products: hadoop
I have a similar issue - if you discover a solution, could you please share
Yes, luckily we found the issue.
In our case, this behavior showing up when reserved template ID (0-255) is received. The issues had been gone when we updated the template ID 256 or larger.
Hope this help.