Elasticstac 40min Data dealy

Hey there,

We have currently running a Netflow setup with Elasticsearch. Data is collected on the Netflow router. Unfortunately it pops up at the Kibana dashboards 40 min later.

What could be the Problem there?

I'm looking forward to your help.

How does it get sent to Elasticsearch?

Netflow Router is sending Netflow packets to Elasticsearch every 5 minutes.
active timeout is set to 5min.

Elasticsearch does not directly accept Netflix so there must be something in between. Please describe this and the corresponding configuration and hardware used.

Ofc., there is a Netflow module configured.


Network plan:

