Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {"level":"info","ts":"2025-02-06T10:13:11.565Z","logger":"flowcoll","caller":"flowcoll/main.go:56","msg":"version","version":"7.3.0"}
- {"level":"info","ts":"2025-02-06T10:13:11.565Z","logger":"flowcoll.license[default]","caller":"envconf/logger.go:49","msg":"EF_ACCOUNT_ID="}
- {"level":"info","ts":"2025-02-06T10:13:11.565Z","logger":"flowcoll.license[default]","caller":"envconf/logger.go:49","msg":"EF_FLOW_LICENSE_KEY="}
- {"level":"info","ts":"2025-02-06T10:13:11.565Z","logger":"flowcoll.license[default]","caller":"envconf/logger.go:49","msg":"EF_FLOW_LICENSED_CORES=0"}
- {"level":"info","ts":"2025-02-06T10:13:11.565Z","logger":"flowcoll.license[default]","caller":"envconf/logger.go:49","msg":"EF_FLOW_LICENSED_UNITS=0"}
- {"level":"info","ts":"2025-02-06T10:13:11.565Z","logger":"flowcoll.license[default]","caller":"envconf/logger.go:49","msg":"EF_LICENSE_ACCEPTED=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.566Z","logger":"flowcoll","caller":"lic/flow.go:51","msg":"By running this software, you and/or the organization using the software agree and are bound to the terms of an ElastiFlow Inc. End-User License Agreement (EULA). For the Community (no license key), Basic and Trial tiers, the applicable license is the ElastiFlow Community EULA, which may be found at: https://www.elastiflow.com/community-license. For Standard and Premium Commercial tiers the applicable license is the ElastiFlow Standard EULA, or other terms agreed in writing with ElastiFlow Inc. The ElastiFlow Standard EULA may be found at: https://www.elastiflow.com/commercial-license."}
- {"level":"info","ts":"2025-02-06T10:13:11.566Z","logger":"flowcoll","caller":"lic/lic.go:49","msg":"license information","expiration":"0001-01-01T00:00:00.000Z","level":0,"units":1}
- {"level":"info","ts":"2025-02-06T10:13:11.567Z","caller":"flowdata/conf.go:482","msg":"Field to Drop: "}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_DECODE_IPFIX_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_DECODE_NETFLOW1_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_DECODE_NETFLOW5_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_DECODE_NETFLOW6_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_DECODE_NETFLOW7_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_DECODE_NETFLOW9_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_DECODE_SFLOW5_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_DECODE_SFLOW_FLOWS_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_DECODE_SFLOW_FLOWS_KEEP_SAMPLES=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_DECODE_SFLOW_COUNTERS_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_DECODE_MAX_RECORDS_PER_PACKET=64"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_TRANSLATE_KEEP_IDS=default"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_APP_ID_ENABLE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_APP_ID_PATH="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_APP_ID_TTL=7200"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_APP_IPPORT_ENABLE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_APP_IPPORT_PATH="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_APP_IPPORT_TTL=7200"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_APP_IPPORT_PRIVATE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_APP_IPPORT_PUBLIC=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_APP_REFRESH_RATE=15"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_OPTION_ENUM_TTL=7200"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_TTL=7200"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_METADATA_ENABLE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_METADATA_USERDEF_PATH="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_METADATA_REFRESH_RATE=15"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_DNS_ENABLE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_DNS_NAMESERVER_IP="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_DNS_NAMESERVER_TIMEOUT=3000"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_DNS_RESOLVE_PRIVATE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_DNS_RESOLVE_PUBLIC=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_DNS_USERDEF_PATH="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_DNS_USERDEF_REFRESH_RATE=15"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_DNS_INCLEXCL_PATH="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_DNS_INCLEXCL_REFRESH_RATE=15"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_NETINTEL_API_ADDR=https://query.netintel.elastiflow.com"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_NETINTEL_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_NETINTEL_INCLEXCL_PATH="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_NETINTEL_INCLEXCL_REFRESH_RATE=15"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_NETINTEL_IP_DB_PATH="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_NETINTEL_REFRESH_RATE=60"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_NETINTEL_TIMEOUT=15"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_NETINTEL_THREAT_COLLECTION_PATH="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_ASN_ENABLE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_ASN_PATH=/etc/elastiflow/maxmind/GeoLite2-ASN.mmdb"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_ENABLE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_PATH=/etc/elastiflow/maxmind/GeoLite2-City.mmdb"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_VALUES=city,country,country_code,location,timezone"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_LANG=en"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_INCLEXCL_PATH="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_INCLEXCL_REFRESH_RATE=15"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_TTL=7200"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_METADATA_ENABLE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_METADATA_USERDEF_PATH="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_METADATA_REFRESH_RATE=15"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_FLOW_OPTIONS_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_ENABLE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_PORT=161"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_VERSION=2"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_COMMUNITIES=public"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_TIMEOUT=2"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_RETRIES=1"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_AUTHORITATIVE_ENGINE_ID="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_AUTHORITATIVE_ENGINE_BOOTS=0"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_AUTHORITATIVE_ENGINE_TIME=0"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_USERNAME="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_AUTHENTICATION_PARAMETERS="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_PRIVACY_PARAMETERS="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_AUTHENTICATION_PROTOCOL=noauth"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_PRIVACY_PROTOCOL=nopriv"}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_AUTHENTICATION_PASSPHRASE="}
- {"level":"info","ts":"2025-02-06T10:13:11.568Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_PRIVACY_PASSPHRASE="}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_SECRET_KEY="}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_PRIVACY_KEY="}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_ACCESS_ENABLE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_ACCESS_PATH=/etc/elastiflow/settings/snmp_access.yml"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_NETIF_SNMP_ACCESS_REFRESH_RATE=15"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_ASN_PREF=lookup"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_TOTALS_IF_NO_DELTAS=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_SAMPLERATE_CACHE_SIZE=32768"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_SAMPLERATE_USERDEF_ENABLE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_SAMPLERATE_USERDEF_PATH=/etc/elastiflow/settings/sample_rate.yml"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_SAMPLERATE_USERDEF_OVERRIDE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_SAMPLERATE_USERDEF_UPSCALE_ENABLE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_SAMPLERATE_USERDEF_UPSCALE_RATE=4"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_COMMUNITYID_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_COMMUNITYID_SEED=0"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_CONVERSATIONID_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_CONVERSATIONID_SEED=0"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_JOIN_ASN=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_JOIN_GEOIP=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_JOIN_SEC=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_JOIN_CLOUD=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_JOIN_NETATTR=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_JOIN_SUBNETATTR=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_DURATION_PRECISION=ms"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_TIMESTAMP_PRECISION=ms"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_PERCENT_NORM=100"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_EXPAND_CLISRV=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_EXPAND_CLISRV_NO_L4_PORTS=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_KEEP_CPU_TICKS=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_POOL_SIZE=4"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_DROP_FIELDS="}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_IFA_ENABLE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_IFA_QUEUE_SIZE=64"}
- {"level":"info","ts":"2025-02-06T10:13:11.569Z","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_IFA_POOL_SIZE=4"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_ECS_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_BATCH_DEADLINE=2000"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_BATCH_MAX_BYTES=8388608"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_TIMESTAMP_SOURCE=start"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_INDEX_PERIOD=rollover"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_INDEX_SUFFIX="}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_OVERWRITE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_ADDRESSES=127.0.0.1:9200"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_USERNAME=elastic"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_PASSWORD=********************"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_CLOUD_ID="}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_API_KEY="}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_CLIENT_CA_CERT_FILEPATH="}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_CLIENT_CERT_FILEPATH="}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_CLIENT_KEY_FILEPATH="}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_TLS_ENABLE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_TLS_SKIP_VERIFICATION=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_TLS_CA_CERT_FILEPATH="}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_RETRY_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_RETRY_ON_TIMEOUT_ENABLE=true"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_MAX_RETRIES=3"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_RETRY_BACKOFF=1000"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_SHARDS=1"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_REPLICAS=0"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_REFRESH_INTERVAL=10s"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_CODEC=best_compression"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_ILM_LIFECYCLE=elastiflow"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_PIPELINE_DEFAULT=_none"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_PIPELINE_FINAL=_none"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_DROP_FIELDS="}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_TIMESTAMP_PRECISION=ms"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_ALLOWED_RECORD_TYPES=as_path_hop,flow_option,flow,ifa_hop,telemetry,metric"}
- {"level":"info","ts":"2025-02-06T10:13:11.570Z","logger":"flowcoll.elasticsearch[default]","caller":"envconf/logger.go:49","msg":"EF_OUTPUT_ELASTICSEARCH_TSDS_ENABLE=false"}
- {"level":"info","ts":"2025-02-06T10:13:11.571Z","logger":"flowcoll.httpserver","caller":"httpserver/httpserver.go:28","msg":"endpoint exposed","url":"http://0.0.0.0:8080/metrics"}
- {"level":"info","ts":"2025-02-06T10:13:11.571Z","logger":"flowcoll.httpserver","caller":"httpserver/httpserver.go:28","msg":"endpoint exposed","url":"http://0.0.0.0:8080/readyz"}
- {"level":"info","ts":"2025-02-06T10:13:11.571Z","logger":"flowcoll.httpserver","caller":"httpserver/httpserver.go:28","msg":"endpoint exposed","url":"http://0.0.0.0:8080/livez"}
- {"level":"info","ts":"2025-02-06T10:13:11.571Z","logger":"flowcoll.httpserver","caller":"httpserver/httpserver.go:28","msg":"endpoint exposed","url":"http://0.0.0.0:8080/support-bundle"}
- {"level":"info","ts":"2025-02-06T10:13:11.573Z","logger":"udpserver[0.0.0.0:2055]","caller":"server/udpserver.go:68","msg":"running","address":"0.0.0.0:2055"}
- {"level":"info","ts":"2025-02-06T10:13:11.593Z","logger":"enricher.app-id_memstore","caller":"appid/memstore.go:73","msg":"listening for entries to store"}
- {"level":"info","ts":"2025-02-06T10:13:11.594Z","logger":"enricher.app-id_memstore","caller":"appid/memstore.go:62","msg":"listening for IPs to delete"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"enricher.ip_memstore","caller":"ip/memstore.go:74","msg":"in-memory store listening for entries to store"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"enricher.ip_memstore","caller":"ip/memstore.go:63","msg":"in-memory store listening for IPs to delete"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"enricher.ip_custodian","caller":"enrichapp/custodian.go:126","msg":"expiration checker is running"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"enricher.appid_custodian","caller":"enrichapp/custodian.go:126","msg":"expiration checker is running"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"enricher.appid_custodian","caller":"enrichapp/custodian.go:105","msg":"listening for IPs to delete"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"enricher.appid_custodian","caller":"enrichapp/custodian.go:116","msg":"listening for entries to store"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"enricher.ip_custodian","caller":"enrichapp/custodian.go:105","msg":"listening for IPs to delete"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"enricher.ip_custodian","caller":"enrichapp/custodian.go:116","msg":"listening for entries to store"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"enum_enricher.memstore","caller":"enum/memstore.go:73","msg":"listening for entries to store"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"enum_enricher.memstore","caller":"enum/memstore.go:62","msg":"listening for enums to delete"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"enum_enricher.custodian","caller":"enrichenum/custodian.go:96","msg":"listening for IPs to delete"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"enum_enricher.custodian","caller":"enrichenum/custodian.go:117","msg":"expiration checker is running"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"enum_enricher.custodian","caller":"enrichenum/custodian.go:107","msg":"listening for entries to store"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"ipaddr_enricher.hostname_enricher","caller":"hostname/hostname.go:73","msg":"started"}
- {"level":"info","ts":"2025-02-06T10:13:11.606Z","logger":"ipaddr_enricher.netintel_threats","caller":"netintel/enricher.go:262","msg":"fetching threat type collection and cidr tree"}
- {"level":"info","ts":"2025-02-06T10:13:12.917Z","logger":"ipaddr_enricher.netintel_threats","caller":"netintel/enricher.go:313","msg":"Threat Type size: 53230 bytes"}
- {"level":"info","ts":"2025-02-06T10:13:20.222Z","logger":"ipaddr_enricher.netintel_threats","caller":"netintel/enricher.go:294","msg":"IPdb size: 246317617 bytes"}
- {"level":"info","ts":"2025-02-06T10:13:30.504Z","logger":"ipaddr_enricher.netintel_threats","caller":"netintel/enricher.go:106","msg":"cidr tree successfully initialized"}
- {"level":"info","ts":"2025-02-06T10:13:30.504Z","logger":"ipaddr_enricher.netintel_threats","caller":"netintel/enricher.go:258","msg":"started"}
- {"level":"info","ts":"2025-02-06T10:13:30.504Z","logger":"ipaddr_enricher.memstore","caller":"enrichipaddr/memstore.go:39","msg":"listening for ips to delete"}
- {"level":"info","ts":"2025-02-06T10:13:30.505Z","logger":"ipaddr_enricher.custodian","caller":"enrichipaddr/custodian.go:63","msg":"listening for entries to store"}
- {"level":"info","ts":"2025-02-06T10:13:30.505Z","logger":"ipaddr_enricher.memstore","caller":"enrichipaddr/memstore.go:50","msg":"store listening for entries to store"}
- {"level":"info","ts":"2025-02-06T10:13:30.505Z","logger":"ipaddr_enricher.custodian","caller":"enrichipaddr/custodian.go:52","msg":"listening for ips to delete"}
- {"level":"info","ts":"2025-02-06T10:13:30.505Z","logger":"ipaddr_enricher.custodian","caller":"enrichipaddr/custodian.go:73","msg":"expiration checker is running"}
- {"level":"info","ts":"2025-02-06T10:13:30.505Z","logger":"netif_enricher","caller":"enrichnetif/memstore.go:41","msg":"in-memory store listening for IPs to delete"}
- {"level":"info","ts":"2025-02-06T10:13:30.505Z","logger":"netif_enricher","caller":"enrichnetif/memstore.go:52","msg":"in-memory store listening for entries to store"}
- {"level":"info","ts":"2025-02-06T10:13:30.505Z","logger":"netif_enricher.custodian","caller":"enrichnetif/custodian.go:55","msg":"listening for IPs to delete"}
- {"level":"info","ts":"2025-02-06T10:13:30.505Z","logger":"netif_enricher.custodian","caller":"enrichnetif/custodian.go:66","msg":"listening for entries to store"}
- {"level":"info","ts":"2025-02-06T10:13:30.505Z","logger":"netif_enricher.custodian","caller":"enrichnetif/custodian.go:76","msg":"expiration checker is running"}
- {"level":"info","ts":"2025-02-06T10:13:30.505Z","logger":"flow_processor","caller":"flowprocessor/flow.go:37","msg":"flow record processor is running"}
- {"level":"info","ts":"2025-02-06T10:13:30.505Z","logger":"flow_processor","caller":"flowprocessor/flow.go:37","msg":"flow record processor is running"}
- {"level":"info","ts":"2025-02-06T10:13:30.505Z","logger":"flow_processor","caller":"flowprocessor/flow.go:37","msg":"flow record processor is running"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"info","ts":"2025-02-06T10:13:30.505Z","logger":"flow_processor","caller":"flowprocessor/flow.go:37","msg":"flow record processor is running"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.2 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.2 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.2 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.2 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.2 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.2 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.506Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.2 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.506Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.2 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.506Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.506Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.2 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.506Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.2 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.506Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.2 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.506Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.506Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.2 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.506Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.506Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.506Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.2 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.506Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.505Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.1 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- {"level":"error","ts":"2025-02-06T10:13:30.506Z","caller":"netflow9/netflow9.go:60","msg":"netflow v9: could not decode flowsets: template not yet received from 10.88.88.2 for session: 40000; you will not see flows until the template is received; this should resolve itself in a few minutes","stacktrace":"github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/netflow9.Decode\n\t/app/pkg/processors/flowprocessor/netflow9/netflow9.go:60\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.decodePacket\n\t/app/pkg/processors/flowprocessor/process/decode.go:88\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket\n\t/app/pkg/processors/flowprocessor/process/process.go:24\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket\n\t/app/pkg/processors/flowprocessor/flow.go:76\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run\n\t/app/pkg/processors/flowprocessor/flow.go:49"}
- panic: interface conversion: interface {} is []interface {}, not uint64
- goroutine 81 [running]:
- github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/enrich.enrichIPaddr({0x1e10b00?, 0xc001f16150?}, {0xc075e77240, 0x10}, 0x3, {0x1277762, 0xd}, 0xc04fbbe1b0, 0xc001941b20)
- /app/pkg/processors/flowprocessor/enrich/utils.go:500 +0x2005
- github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/enrich.ipAddr(0xc04fbbe2a0, 0xc04fbbe1b0, 0xc0b398f200, 0xc001951500)
- /app/pkg/processors/flowprocessor/enrich/ip.go:33 +0x89a
- github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/enrich.EnrichRawIE(...)
- /app/pkg/processors/flowprocessor/enrich/enrich.go:60
- github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/enrich.EnrichRecord(0xc0000be060, 0xc0b398f200, 0xc001951500)
- /app/pkg/processors/flowprocessor/enrich/enrich.go:73 +0x16b
- github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/enrich.EnrichRecords(...)
- /app/pkg/processors/flowprocessor/enrich/enrich.go:79
- github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.processDecodedRecords({0xc04fba3640, 0x8, 0x8}, 0xc001951500, 0xc0b398f200, 0x0, 0x0)
- /app/pkg/processors/flowprocessor/process/process.go:49 +0x4d2
- github.com/elastiflow/flowcoll/pkg/processors/flowprocessor/process.ProcessPacket({0xc075e76b40?, 0x10?, 0x0?}, 0xc000100000?, {0xc0a1f34000?, 0x4596b8?, 0x0?}, 0x10?, 0xc0b398f200, 0xc001951500, ...)
- /app/pkg/processors/flowprocessor/process/process.go:29 +0x5f
- github.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).decodePacket(0xc07560ef30, {{0x1e11f38, 0xc0a1f29320}, 0xc0a3fb8480, 0x3b8, 0x194dac01798})
- /app/pkg/processors/flowprocessor/flow.go:76 +0x2e5
- github.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*FlowProcessor).Run(0xc07560ef30, {0x1e15f50, 0xc001610820})
- /app/pkg/processors/flowprocessor/flow.go:49 +0x405
- created by github.com/elastiflow/flowcoll/pkg/processors/flowprocessor.(*Pool).Run in goroutine 216
- /app/pkg/processors/flowprocessor/pool.go:62 +0x23b
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement