To configure IPFIX with extensions flow reporting
In the Settings section, for Report Connections, select one of these radio buttons:
This step is optional, but is required if flow reporting is done on selected interfaces.
Select Send Flows and Real-Time Data To External Collector.
When enabling this option, you might need to reboot the device to enable this feature completely.
For the Source IP to Use for Collector on a VPN Tunnel, specify the source IP if the external collector must be reached by a VPN tunnel.
This step is required if the external collector must be reached by a VPN tunnel.
Select any additional reports to be generated to a flow from the Include Following Additional Reports via IPFIX drop-down menu.
To have system logs generated, you must select System Logs from this drop-down menu.
Click Generate ALL Templates to begin generating templates.
IPFIX with extensions uses templates that must be known to an external collector before sending data.
To send log messages to the external collector, click Send All Entries for the Send Log Settings to External Collector option.
Ensure the connection between SonicOS on the firewall and the external collector server is ready before clicking Send All Entries.
The external server loads the properties (see Saved properties) and settings for use when it reboots. Click Send All Entries to synchronize the settings whenever:
SonicOS sends updates to the external server automatically if some fields of log event settings are changed.
Category | Property | |
---|---|---|
Event properties and settings | Event ID
Belongs to group ID Color Message type ID |
Priority
Stream filter Event name Log message |
Group properties | Group ID
Belongs to category ID |
Group name |
Category properties | Category ID | Category name |
Message type properties | Type ID | Type name |
Click Accept.