# Netflow V9 : message=\>"No matching template for flow id 279"

**URL:** <https://discuss.elastic.co/t/netflow-v9-message-no-matching-template-for-flow-id-279/56269>\
**Category:** Logstash\
**Created:** [July 25, 2016, 8:09am UTC](https://discuss.elastic.co/t/netflow-v9-message-no-matching-template-for-flow-id-279/56269 "2016-07-25T08:09:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![solidz](https://avatars.discourse-cdn.com/v4/letter/s/bbe5ce/32.png) [@solidz](https://discuss.elastic.co/u/solidz)\
**Post date:** [July 25, 2016, 8:09am UTC](https://discuss.elastic.co/t/netflow-v9-message-no-matching-template-for-flow-id-279/56269/1 "2016-07-25T08:09:12Z")

</div>

Hi,

I have configured Netflow V9 on my Cisco Router and I have installed Logstash 2.3.4 on my CentOS Server. I know that my Netflow configuration on my router is correct because I started a Wireshark capture and results seems good.  
When I start Logstash service, I have this following error in Logstash logs :

```
09:46:44.328000+0200", :message=>"Pipeline main started"}
{:timestamp=>"2016-07-25T09:47:16.941000+0200", :message=>"No matching template for flow id 279", :level=>:warn}
{:timestamp=>"2016-07-25T09:47:16.952000+0200", :message=>"No matching template for flow id 279", :level=>:warn}
{:timestamp=>"2016-07-25T09:47:21.909000+0200", :message=>"No matching template for flow id 279", :level=>:warn}
{:timestamp=>"2016-07-25T09:47:21.915000+0200", :message=>"No matching template for flow id 279", :level=>:warn}
{:timestamp=>"2016-07-25T09:47:26.896000+0200", :message=>"No matching template for flow id 279", :level=>:warn}
{:timestamp=>"2016-07-25T09:47:26.902000+0200", :message=>"No matching template for flow id 279", :level=>:warn}

```

I don't understand the reason why this message appears..

My Logstash configuration :

```
input {
    udp {
        port => 9995
        type => netflow
        codec => netflow {
            netflow_definitions => "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-codec-netflow-2.1.1/lib/logstash/codecs/netflow/netflow.yaml" # Dictionnaire NetFlow
            versions => [9]        
        }
    }
}

filter {

}

output {
    stdout { codec => rubydebug }
    file {
        path => "/var/log/logstash/test"
    }
}

```

Any idea ?

Thanks for answers.

PS : I use the plugin logstash-codec-netflow-2.1.1

---

<div class="post-metadata">

**Author:** ![Iroel](https://avatars.discourse-cdn.com/v4/letter/i/e9a140/32.png) [@Iroel](https://discuss.elastic.co/u/Iroel)\
**Post date:** [July 27, 2016, 8:47pm UTC](https://discuss.elastic.co/t/netflow-v9-message-no-matching-template-for-flow-id-279/56269/2 "2016-07-27T20:47:00Z")

</div>

Hi,

Try to add these lines to your netflow.yaml file:

> 128:
> 
> - 2
> - :dst\_as  
> 129:
> - 2
> - :src\_as

Regards,

Iro

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:46am UTC](https://discuss.elastic.co/t/netflow-v9-message-no-matching-template-for-flow-id-279/56269/3 "2017-07-06T04:46:11Z")

</div>


