Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Nfdump - wrong date / timestamp on Cisco Viptela SD-WAN devices #585

Open
Cameron-84 opened this issue Dec 17, 2024 · 2 comments
Open

Nfdump - wrong date / timestamp on Cisco Viptela SD-WAN devices #585

Cameron-84 opened this issue Dec 17, 2024 · 2 comments
Assignees

Comments

@Cameron-84
Copy link

Cameron-84 commented Dec 17, 2024

Hello,

I have similar issue as was mentioned here: #397 with bad date / timestamp.
There was no problem in the earlier version 1.6.x. My current version is 1.7.5 (latest).
Devices: Cisco Viptela SD-WAN vEdge routers (practically no netflow customisable settings).
image

My troubleshooting output's:
image

image

image

image

Device time is synced with NTP servers.
Nfdump compiled with "--enable-nfprofile --enable-nftrack --enable-sflow" (I also tried "--enable-nsel" but has no effect...).
Thanks for your help.

@phaag
Copy link
Owner

phaag commented Dec 18, 2024

The timestamp you have marked in red is the time, when the ipfix packet has been exported from the CISCO device and does not correspond with the time of the flows start/stop, which are sent by that ipfix packet. You need to check the template, which is associated with that flow. However, it looks like a malformed package for some reason.
If you have difficulties in debugging the package stream feel free to send me a pcap of the traffic, sent to the collector, which contains enough information (template and data records), so I can check for you.

@phaag phaag self-assigned this Dec 18, 2024
@Cameron-84
Copy link
Author

Thanks for response.
Here is pcap of the traffic: cflowd.pcap.zip

image

image

image

Thank you very much for your help.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants