Hi
I've just instaledd td-agent and fluent-plugin-netflow v0.0.3 to integrate ellasticsearch and kibana3 with them, and run into the issue.
Fluent-plugin-netflow cannot parse netflowv9 message from Cisco ASR1K for now.
I attach the pcap file captured the netflow messages.
Please ask me if I can give you more info.
2014-07-13 16:22:48 -0700 [info]: fluent/engine.rb:102:block in configure: adding source type="netflow"
2014-07-13 16:22:48 -0700 [trace]: fluent/plugin.rb:72:register_impl: registered input plugin 'netflow'
2014-07-13 16:22:48 -0700 [info]: fluent/engine.rb:102:block in configure: adding source type="http"
2014-07-13 16:22:48 -0700 [info]: fluent/engine.rb:118:block in configure: adding match pattern="netflow.*" type="elasticsearch"
2014-07-13 16:22:48 -0700 [trace]: fluent/plugin.rb:72:register_impl: registered output plugin 'elasticsearch'
2014-07-13 16:22:48 -0700 [debug]: plugin/in_netflow
.rb:92
:listen: listening
netflow socket on
192.168.40.113:5140 with
udp
2014-07-13 16:23:16 -0700 [debug]: plugin/in_netflow.rb:73:receive_data: received logs host="10.0.201.31" data="\x00\t\x00\x01x\xEB\xA8dS\xC3\x14\xF6\x00\x00BG\x00\x00\x01\x00\x00\x00\x00D\x01\n\x00\x0F\x00\b\x00\x04\x00\f\x00\x04\x00<\x00\x01\x00\x04\x00\x01\x00\a\x00\x02\x00\v\x00\x02\x008\x00\x06\x00P\x00\x06\x00Q\x00\x06\x009\x00\x06\x000\x00\x01\x00\x01\x00\b\x00\x02\x00\x04\x00\x16\x00\x04\x00\x15\x00\x04"
2014-07-13 16:24:16 -0700 [debug]: plugin/in_netflow.rb:73:receive_data: received logs host="10.0.201.31" data="\x00\t\x00\x01x\xEC\x92\xC4S\xC3\x152\x00\x00BH\x00\x00\x01\x00\x00\x00\x00D\x01\n\x00\x0F\x00\b\x00\x04\x00\f\x00\x04\x00<\x00\x01\x00\x04\x00\x01\x00\a\x00\x02\x00\v\x00\x02\x008\x00\x06\x00P\x00\x06\x00Q\x00\x06\x009\x00\x06\x000\x00\x01\x00\x01\x00\b\x00\x02\x00\x04\x00\x16\x00\x04\x00\x15\x00\x04"
2014-07-13 16:25:16 -0700 [debug]: plugin/in_netflow.rb:73:receive_data: received logs host="10.0.201.31" data="\x00\t\x00\x01x\xED}$S\xC3\x15n\x00\x00BI\x00\x00\x01\x00\x00\x00\x00D\x01\n\x00\x0F\x00\b\x00\x04\x00\f\x00\x04\x00<\x00\x01\x00\x04\x00\x01\x00\a\x00\x02\x00\v\x00\x02\x008\x00\x06\x00P\x00\x06\x00Q\x00\x06\x009\x00\x06\x000\x00\x01\x00\x01\x00\b\x00\x02\x00\x04\x00\x16\x00\x04\x00\x15\x00\x04"
2014-07-13 16:25:47 -0700 [debug]: plugin/in_netflow.rb:73:receive_data: received logs host="10.0.201.31" data="\x00\t\x00\x01x\xED\xF5\x15S\xC3\x15\x8C\x00\x00BJ\x00\x00\x01\x00\x01\n\x00@\xAC\x1Ef\xD3\b\b\b\b\x04\x11\xC1\xB0\x005\xB8x.\x915Y|i\xF6(\xBD\x00|i\xF6(\xBD\x00PW\xA8\x83\x97\x81\x00\x00\x00\x00\x00\x00\x00\x01\xEA\x00\x00\x00\ax\xED\xBA>x\xED\xBAF\x00"
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:85:rescue in receive_data: "\x00\t\x00\x01x\xED\xF5\x15S\xC3\x15\x8C\x00\x00BJ\x00\x00\x01\x00\x01\n\x00@\xAC\x1Ef\xD3\b\b\b\b\x04\x11\xC1\xB0\x005\xB8x.\x915Y|i\xF6(\xBD\x00|i\xF6(\xBD\x00PW\xA8\x83\x97\x81\x00\x00\x00\x00\x00\x00\x00\x01\xEA\x00\x00\x00\ax\xED\xBA>x\xED\xBAF\x00" error="wrong number of arguments (1 for 0)"
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/base.rb:191:in `to_s'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/fluent-plugin-netflow-0.0.3/lib/fluent/plugin/parser_netflow.rb:280:in `block in get'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/array.rb:208:in `block in each'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/array.rb:208:in `each'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/array.rb:208:in `each'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/fluent-plugin-netflow-0.0.3/lib/fluent/plugin/parser_netflow.rb:280:in `collect'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/fluent-plugin-netflow-0.0.3/lib/fluent/plugin/parser_netflow.rb:280:in `get'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/primitive.rb:111:in `sensible_default'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/base_primitive.rb:142:in `_value'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/primitive.rb:103:in `do_num_bytes'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/struct.rb:250:in `block in sum_num_bytes_below_index'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/struct.rb:247:in `each'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/struct.rb:247:in `inject'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/struct.rb:247:in `sum_num_bytes_below_index'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/struct.rb:243:in `sum_num_bytes_for_all_fields'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/struct.rb:141:in `do_num_bytes'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/base.rb:174:in `num_bytes'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/fluent-plugin-netflow-0.0.3/lib/fluent/plugin/parser_netflow.rb:163:in `block in call'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/array.rb:208:in `block in each'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/array.rb:208:in `each'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/bindata-2.1.0/lib/bindata/array.rb:208:in `each'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/fluent-plugin-netflow-0.0.3/lib/fluent/plugin/parser_netflow.rb:63:in `call'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/fluent-plugin-netflow-0.0.3/lib/fluent/plugin/in_netflow.rb:75:in `receive_data'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/fluent-plugin-netflow-0.0.3/lib/fluent/plugin/in_netflow.rb:111:in `call'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/fluent-plugin-netflow-0.0.3/lib/fluent/plugin/in_netflow.rb:111:in `on_readable'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/cool.io-1.1.1/lib/cool.io/io.rb:170:in `on_readable'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/cool.io-1.1.1/lib/cool.io/loop.rb:96:in `run_once'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/cool.io-1.1.1/lib/cool.io/loop.rb:96:in `run'
2014-07-13 16:25:47 -0700 [warn]: plugin/in_netflow.rb:111:call: /usr/lib/fluent/ruby/lib/ruby/gems/1.9.1/gems/fluent-plugin-netflow-0.0.3/lib/fluent/plugin/in_netflow.rb:64:in `run'
2014-07-13 16:25:48 -0700 [debug]: plugin/in_netflow.rb:73:receive_data: received logs host="10.0.201.31" data="\x00\t\x00\x02x\xED\xF8\xFDS\xC3\x15\x8D\x00\x00BK\x00\x00\x01\x00\x01\n\x00|\xAC\x1Ef\xD3J}\x14T\x04\x06\xE5\x85\x01\xBB\xB8x.\x915Y|i\xF6(\xBD\x00|i\xF6(\xBD\x00PW\xA8\x83\x97\x81\x00\x00\x00\x00\x00\x00\x00\x01\x05\x00\x00\x00\x04x\xED\xBAFx\xED\xBD\xB8\xAC\x1Ef\xD3J}\x14_\x04\x06\xE5\x86\x01\xBB\xB8x.\x915Y|i\xF6(\xBD\x00|i\xF6(\xBD\x00PW\xA8\x83\x97\x81\x00\x00\x00\x00\x00\x00\x00\x01\x05\x00\x00\x00\x04x\xED\xBAFx\xED\xBD\xB0\x00\x00"
2014-07-13 16:25:48 -0700 [warn]: plugin/in_netflow.rb:85:rescue in receive_data: "\x00\t\x00\x02x\xED\xF8\xFDS\xC3\x15\x8D\x00\x00BK\x00\x00\x01\x00\x01\n\x00|\xAC\x1Ef\xD3J}\x14T\x04\x06\xE5\x85\x01\xBB\xB8x.\x915Y|i\xF6(\xBD\x00|i\xF6(\xBD\x00PW\xA8\x83\x97\x81\x00\x00\x00\x00\x00\x00\x00\x01\x05\x00\x00\x00\x04x\xED\xBAFx\xED\xBD\xB8\xAC\x1Ef\xD3J}\x14_\x04\x06\xE5\x86\x01\xBB\xB8x.\x915Y|i\xF6(\xBD\x00|i\xF6(\xBD\x00PW\xA8\x83\x97\x81\x00\x00\x00\x00\x00\x00\x00\x01\x05\x00\x00\x00\x04x\xED\xBAFx\xED\xBD\xB0\x00\x00" error="wrong number of arguments (1 for 0)"
Any comments and advoices will be appreciated.
Regards,
Koh