Page 1 of 1

Queries to view 15 minutes

Posted: Fri Feb 10, 2017 9:51 am
by ies
I am testing out Nagios Netflow and am running into an issue. I have been collecting data into a source for the last 14 hours or so. If i run a query to show the last 15 minutes it didn't show any data. It reports back "No query data was returned for your query."

Here is my query:
Aggregate By: dstip,srcip
Time Frame: Custom Elapsed Time
15 minutes ago

I dont have anything in the Raw Query. To get it to display any data i have to go all the way up to 6 hours. That wont help our guys troubleshoot as well as being able to only look at the last 15 minutes.

Re: Queries to view 15 minutes

Posted: Fri Feb 10, 2017 1:50 pm
by ies
I ended up rebuilding the server scratch without the OVA because I was having some other issues. After the rebuild I am able to query to 15 mins. Not sure what was wrong with the original install but it wasn't worth the time to keep troubleshooting.

Re: Queries to view 15 minutes

Posted: Fri Feb 10, 2017 2:46 pm
by rkennedy
Hard to say what could have happened - but, glad to hear it worked properly now! Are we good to mark this thread as resolved?

Re: Queries to view 15 minutes

Posted: Tue Feb 21, 2017 7:53 am
by ies
yep