Visualizing Netflow version 9 on ELK
prerequirement
- Elasticsearch / Logstash / Kibana are enabled
see also
Amazon AWS Elastic Stack
vagrant and elk stack installation - firewalld is permitting netflow export port
router setting
1 | sho ver |
1 | flow record ELK-r |
start logstash service
/opt/logstash/bin/logstash -f /etc/logstash/conf.d/1-netflow.conf &
If collector correctly begin to receive netflow, console looks like:
1 | { |
If you see error messages like:
1 | No matching template for flow id 260 {:level=>:warn} |
You could define length or skip
them.
vi /etc/logstash/codec/v9.yaml
1 | 260: |