Troubleshooting NSEL data flows
Troubleshooting NSEL data flows is a verification process that
-
verifies that NSEL events are being sent from your ASA to the Cisco Cloud
-
confirms that the Cisco Cloud is receiving NSEL events, and
-
uses flow-export counters and capture commands to diagnose data flow issues.
NSEL data flow verification requirements
Once you have configured Netflow Secure Event Logging (NSEL), data does not flow immediately. It could take a few minutes for the first NSEL packets to arrive assuming there is NSEL-related traffic being generated on the ASA.
This verification process involves these tasks:
-
Verify that NetFlow Packets are Being Sent to the SEC
-
Verify that NetFlow Packets are Being Received by the Cisco Cloud
Note | This workflow shows you a straight-forward use of the "flow-export counters" command and "capture" commands to Troubleshoot NSEL Data Flows. See "Packet Captures" CLI Book 1: Cisco ASA Series General Operations CLI Configuration Guide and "Monitoring NSEL" in the Cisco ASA NetFlow Implementation Guide for a more detailed discussion of the usage of these commands. |