User's Guide

Table Of Contents
Appendix: Files
214 of 218
5. Go to Kibana at http://YOUR_KIBANA_SERVER_IP:5601.
6. Select Dashboard.
7. Click on ElastiFlow: Overview.
You should see some data.
8. The Logstash log file displays the following message:
[WARN ][logstash.codecs.netflow ] Can't (yet) decode
flowset id xxx from observation domain id xxxx, because no
template to decode it with has been received.
This message is normal. It goes away after one minute when Logstash
receives the IPFIX data template, and this message will stop being added
to the log file.
Appendix: Files
Additions to ipfix.yml in extr_elastiflow_3.4.2.tar.gz
# Extreme Networks (formerly 'Enterasys')
1916:
0:
- :skip
371:
- :string
- :extr_userName
372:
- :string
- :extr_appGroupName
1000:
- :string
- :extr_srcHostName
1001:
- :string
- :extr_dstHostName
1002:
- :uint64
- :extr_netResponseTime
1003:
- :uint64