Observability
NetFlow v9 Flows Not Processed Due to Missing Required Fields (InterfaceRx/InterfaceTx) in SolarWinds NTA
SolarWinds NTA generates alerts indicating that NetFlow data is being received but cannot be processed due to missing required fields in the NetFlow v9 template. Additionally, interfaces sending flow data are not managed or monitored in SolarWinds, leading to visibility gaps in traffic analysis.
First published date
Last published date
Overview
This issue occurs when the exporting device does not include mandatory fields required by SolarWinds NTA:
- InterfaceRx (Input Interface Index)
- InterfaceTx (Output Interface Index)
Without these fields, NTA cannot map traffic correctly to interfaces. Additionally, alerts appear when flow data is received from interfaces not added or enabled for monitoring.
Product section
Resolution
- Verify NetFlow export configuration on the device and ensure it is sending data to the SolarWinds NTA server IP with the correct port (default UDP 2055)
- Ensure the NetFlow v9 or Flexible NetFlow template includes required fields:
- InterfaceRx (Field Type 10)
- InterfaceTx (Field Type 14)
- Update or modify the flow record configuration on the device to include input and output interface fields
- Confirm that NetFlow templates are being exported correctly; restart the flow export process if needed to refresh templates
- Add unmanaged interfaces in SolarWinds by navigating to the node and selecting Add this interface or managing interfaces manually
- Enable NetFlow analysis on the required interfaces within SolarWinds NTA
- Verify that required firewall ports (e.g., UDP 2055) are open between the device and the SolarWinds server
- Validate flow data in the NTA Summary page and confirm that traffic is properly displayed per interface
Additional Notes:
- Devices lacking support for the required NetFlow fields may not be fully compatible with NTA
- A firmware upgrade may be required on certain Cisco devices
- Reference: Required fields in SolarWinds NTA