# IPFIX Input issue 2

**URL:** <https://community.graylog.org/t/ipfix-input-issue-2/20262>\
**Category:** Graylog Tech Challenges\
**Created:** [June 22, 2021, 6:40pm UTC](https://community.graylog.org/t/ipfix-input-issue-2/20262 "2021-06-22T18:40:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![djames000](https://avatars.discourse-cdn.com/v4/letter/d/3da27b/32.png) [@djames000](https://community.graylog.org/u/djames000)\
**Post date:** [June 22, 2021, 6:40pm UTC](https://community.graylog.org/t/ipfix-input-issue-2/20262/1 "2021-06-22T18:40:07Z")

</div>

I opened up a community account to request help on this same issue. I’ve experienced the same issues as [aazherelyeu](https://community.graylog.org/t/daily-challenge-ipfix-input-issue/20079/10) when trying to ingest Netflow messages from vSphere.

I’m able to collect Netflow messages from PFSense with the Netflow input without any issue, but vSphere only provides the option to send Netflow v10/IPFIX messages.

Has anyone had any luck in creating a definition file for IPFIX? My suspicion is that there may be an error in how I created the file, but I haven’t been able to find a guide on how it should be done.

---

<div class="post-metadata">

**Author:** ![dscryber](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dscryber/32/14178_2.png) [@dscryber](https://community.graylog.org/u/dscryber)\
**Post date:** [June 22, 2021, 6:45pm UTC](https://community.graylog.org/t/ipfix-input-issue-2/20262/2 "2021-06-22T18:45:55Z")

</div>

Welcome to the community, djames000! Glad you’re here.

I’ve split your post from [aazherelyeu’s](https://community.graylog.org/t/daily-challenge-ipfix-input-issue/20079/10) to help members find it more readily.

---

<div class="post-metadata">

**Author:** ![aazherelyeu](https://avatars.discourse-cdn.com/v4/letter/a/34f0e0/32.png) [@aazherelyeu](https://community.graylog.org/u/aazherelyeu)\
**Post date:** [June 28, 2021, 7:50am UTC](https://community.graylog.org/t/ipfix-input-issue-2/20262/3 "2021-06-28T07:50:04Z")

</div>

Hello,

I’d share my definitions files for both ipfix and velocloud but I can’t attach them here. Here you are an example for ipfix:

{  
“enterprise\_number”: 29305,  
“information\_elements”: [  
{  
“element\_id”: 1,  
“name”: “octetDeltaCount”,  
“data\_type”: “unsigned64”  
},  
{  
“element\_id”: 2,  
“name”: “packetDeltaCount”,  
“data\_type”: “unsigned64”  
},  
{  
“element\_id”: 3,  
“name”: “deltaFlowCount”,  
“data\_type”: “unsigned64”  
},  
…  
…  
…  
{  
“element\_id”: 491,  
“name”: “bgpDestinationLargeCommunityList”,  
“data\_type”: “basicList”  
}  
]  
}

If you had an issue with definition files Graylog would tell you about that in graylog.log.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [June 28, 2021, 10:01pm UTC](https://community.graylog.org/t/ipfix-input-issue-2/20262/4 "2021-06-28T22:01:26Z")

</div>

@djames000

> [@djames000](#):
>
> but vSphere only provides the option to send Netflow v10/IPFIX messages

I think this might be the problem, since Netflow plugin supports NetFlow V9 and your device is running V10. It might be something with the version not matching, but I’m not 100% sure.

---

<div class="post-metadata">

**Author:** ![djames000](https://avatars.discourse-cdn.com/v4/letter/d/3da27b/32.png) [@djames000](https://community.graylog.org/u/djames000)\
**Post date:** [June 29, 2021, 3:37pm UTC](https://community.graylog.org/t/ipfix-input-issue-2/20262/5 "2021-06-29T15:37:30Z")

</div>

Thanks, aazherelyeu! I misinterpreted the Graylog IPFIX manual ( [IPFIX Input — Graylog 4.0.0 documentation](https://docs.graylog.org/en/4.0/pages/integrations/inputs/ipfix_input.html) ) and originally placed the value codes in the data\_type field instead of the descriptions, so I had this:

```auto
    {
      "element_id": 880,
      "name": "tenantProtocol",
      "data_type": "1"
    },

```

instead of this:

```auto
{
      "element_id": 880,
      "name": "tenantProtocol",
      "data_type": "unsigned8"
    },

```

Making that switch cleared up my “org.graylog.integrations.ipfix.IpfixException: Missing information element definitions for private enterprise number 6876” error.

I also had another error message in graylog.log, “Unable to read information element definition file  
com.fasterxml.jackson.core.JsonParseException: Unexpected character (’]’ (code 93)): expected a value”, but that was cleared up by removing an extra comma after the last elemet\_id block.

Thanks, gsmith. I did try using an IPFIX UDP input, but that didn’t work until I fixed the IPFIX field definitions file.

For anyone that comes across this in the future, here is the VMWare reference I used to build my json file, and the json file itself to interpret the vSphere NetFlow messages:

> **[Flows Monitored by the IPFIX for vSphere Distributed Switch](https://docs.vmware.com/en/VMware-NSX-Data-Center-for-vSphere/6.4/com.vmware.nsx.admin.doc/GUID-40805D0E-8A97-4011-B85C-CBF37812DBB5.html)**
>
> The preceding diagrams show the communication between the two VMs running on two different hosts and the flows monitored by the IPFIX feature for vSphere Distributed Switch.

```auto
{
  "enterprise_number": 6876,
  "information_elements": [
    {
      "element_id": 880,
      "name": "tenantProtocol",
      "data_type": "unsigned8"
    },
    {
      "element_id": 881,
      "name": "tenantSourceIPv4",
      "data_type": "ipv4Address"
    },
    {
      "element_id": 882,
      "name": "tenantDestIPv4",
      "data_type": "ipv4Address"
    },
    {
      "element_id": 883,
      "name": "tenantSourceIPv6",
      "data_type": "ipv6Address"
    },
    {
      "element_id": 884,
      "name": "tenantDestIPv6",
      "data_type": "ipv6Address"
    },
    {
      "element_id": 886,
      "name": "tenantSourcePort",
      "data_type": "unsigned16"
    },
    {
      "element_id": 887,
      "name": "tenantDestPort",
      "data_type": "unsigned16"
    },
    {
      "element_id": 888,
      "name": "egressInterfaceAttr",
      "data_type": "unsigned16"
    },
    {
      "element_id": 889,
      "name": "vxlanExportRole",
      "data_type": "unsigned8"
    },
    {
      "element_id": 890,
      "name": "ingressInterfaceAttr",
      "data_type": "unsigned16"
    },
  ]
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [July 13, 2021, 3:37pm UTC](https://community.graylog.org/t/ipfix-input-issue-2/20262/6 "2021-07-13T15:37:59Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
