unfortunately F5 sFlow is currently not supported by NTA. Would you mind sending us a WireShark pcap with couple of minutes of sFlow from F5 device?
You can use leapfile for that purpose, see Leapfile Instructions
Thanks in advance!
definitely still looking for them!
If you would be so kind, please create a short (5-15 minutes) pcap using wireshark, showing just udp packets heading your flows collector and with source IP belonging to the F5 device, so wireshark filter will look similar to this: udp.port==2055 && ip.src==10.114.75.24.
Then please upload the pcap file to solarwinds leapfile:
- Navigate to http://solarwinds.leapfile.com
- Select the Secure Upload option
- Enter firstname.lastname@example.org as the recipient email address
- Fill out the form and provide some information about your issue in the subject line.
- Select the Select Files To Send (Regular Upload) option
- Browse to the compressed capture file
- Select the Upload & Send button
thanks for prompt reaction, however in provided pcap unfortunately aren't any sflow data usable by NTA :-( It seems that device is exporting only counter samples (statistics about amounts of packets traversing through device interfaces, pretty much the same information you get by monitoring using strandard snmp).
According to this article: sFlow: Configuring F5 BIG-IP it seems that F5 released newer TMOS 11.4.0 in June, that should bring full sFlow support including packet sampling - the type of info that NTA collects.
If you plan to upgrade to the TMOS 11.4.0, I would be pleased if you could then provide a packet capture once again.