Summary
{
"_index": ".ds-logs-netflow.log-default-2024.12.09-001458",
"_id": "tO47qpMBV6TtyLZf-NUY",
"_version": 1,
"_score": 0,
"_source": {
"agent": {
"name": "logstash02",
"id": "82cca-0b9-4c5-ab7-72e68b",
"type": "filebeat",
"ephemeral_id": "1ce4-f3cb-401-a657-4c9d",
"version": "8.7.0"
},
"destination": {
"geo": {
"country_iso_code": "SA",
"timezone": "Asia/Riyadh",
"country_name": "Saudi Arabia",
"continent_code": "AS",
"location": {
"lon": 45,
"lat": 25
}
},
"port": 443,
"ip": "185.145.130.86",
"locality": "external"
},
"source": {
"geo": {
"region_iso_code": "SA-01",
"city_name": "Riyadh",
"country_iso_code": "SA",
"timezone": "Asia/Riyadh",
"country_name": "Saudi Arabia",
"continent_code": "AS",
"region_name": "Ar Riyāḑ",
"location": {
"lon": 6.752,
"lat": 4.637
}
},
"port": 43573,
"bytes": 82,
"ip": "45.182.16.3",
"locality": "external",
"packets": 2
},
"fileset": {
"name": "log"
},
"network": {
"community_id": "1:zqjXrBRFF4dfdggYPo=",
"bytes": 82,
"transport": "tcp",
"type": "ipv4",
"iana_number": "6",
"packets": 2,
"direction": "external"
},
"tags": [
"forwarded",
"beats_input_raw_event",
"_geoip_database_unavailable_GeoLite2-ASN.mmdb",
"_geoip_database_unavailable_GeoLite2-ASN.mmdb"
],
"observer": {
"ip": "10.10.14.20"
},
"input": {
"type": "netflow"
},
"netflow": {
"destination_ipv4_address": "185.145.130.86",
"packet_delta_count": 2,
"source_ipv4_address": "45.182.16.3",
"protocol_identifier": 6,
"exporter": {
"uptime_millis": 398541755,
"address": "10.10.14.20:645",
"ip": "10.10.14.20",
"source_id": 256,
"version": 9,
"timestamp": "2024-12-09T07:03:53.000Z"
},
"tcp_control_bits": 16,
"octet_delta_count": 82,
"egress_interface": 20,
"ingress_interface": 18,
"type": "netflow_flow",
"destination_transport_port": 443,
"source_transport_port": 43573
},
"@timestamp": "2024-12-09T07:04:26.914Z",
"related": {
"ip": [
"45.182.16.3",
"185.145.130.86"
]
},
"ecs": {
"version": "8.6.0"
},
"service": {
"type": "netflow"
},
"data_stream": {
"namespace": "default",
"type": "logs",
"dataset": "netflow.log"
},
"@version": "1",
"event": {
"agent_id_status": "auth_metadata_missing",
"ingested": "2024-12-09T07:04:36Z",
"created": "2024-12-09T07:04:26.914Z",
"kind": "event",
"module": "netflow",
"action": "netflow_flow",
"category": [
"network"
],
"type": [
"connection"
],
"dataset": "netflow.log"
},
"flow": {
"locality": "external",
"id": "7sr-eX2CCV"
}
},
"fields": {
"event.ingested": [
"2024-12-09T07:04:36.000Z"
],
"@timestamp": [
"2024-12-09T07:04:26.914Z"
],
"event.created": [
"2024-12-09T07:04:26.914Z"
],
"netflow.exporter.timestamp": [
"2024-12-09T07:03:53.000Z"
]
}
}
{
"_index": ".ds-logs-netflow.log-default-2024.12.09-001458",
"_id": "t-47qpMBV6TtyLZf-NUY",
"_version": 1,
"_score": 0,
"_source": {
"agent": {
"name": "logstash02",
"id": "82cca-0b9-4c5-ab7-72e68b",
"type": "filebeat",
"ephemeral_id": "1ce4-f3cb-401-a657-4c9d",
"version": "8.7.0"
},
"destination": {
"geo": {
"country_iso_code": "SA",
"timezone": "Asia/Riyadh",
"country_name": "Saudi Arabia",
"continent_code": "AS",
"location": {
"lon": 45,
"lat": 25
}
},
"port": 443,
"ip": "185.145.130.86",
"locality": "external"
},
"source": {
"geo": {
"country_iso_code": "SA",
"timezone": "Asia/Riyadh",
"country_name": "Saudi Arabia",
"continent_code": "AS",
"location": {
"lon": 45,
"lat": 25
}
},
"port": 62540,
"bytes": 82,
"ip": "174.140.0.207",
"locality": "external",
"packets": 2
},
"fileset": {
"name": "log"
},
"network": {
"community_id": "1:hvIAxyvabjwMMyuPdb8US/ljuUw=",
"bytes": 82,
"transport": "tcp",
"type": "ipv4",
"iana_number": "6",
"packets": 2,
"direction": "external"
},
"tags": [
"forwarded",
"beats_input_raw_event",
"_geoip_database_unavailable_GeoLite2-ASN.mmdb",
"_geoip_database_unavailable_GeoLite2-ASN.mmdb"
],
"observer": {
"ip": "10.10.14.20"
},
"input": {
"type": "netflow"
},
"netflow": {
"destination_ipv4_address": "185.145.130.86",
"packet_delta_count": 2,
"source_ipv4_address": "174.140.0.207",
"protocol_identifier": 6,
"exporter": {
"uptime_millis": 398541738,
"address": "10.10.14.20:645",
"ip": "10.10.14.20",
"source_id": 256,
"version": 9,
"timestamp": "2024-12-09T07:03:53.000Z"
},
"tcp_control_bits": 16,
"octet_delta_count": 82,
"egress_interface": 20,
"ingress_interface": 18,
"type": "netflow_flow",
"destination_transport_port": 443,
"source_transport_port": 62540
},
"@timestamp": "2024-12-09T07:04:26.879Z",
"related": {
"ip": [
"174.140.0.207",
"185.145.130.86"
]
},
"ecs": {
"version": "8.6.0"
},
"service": {
"type": "netflow"
},
"data_stream": {
"namespace": "default",
"type": "logs",
"dataset": "netflow.log"
},
"@version": "1",
"event": {
"agent_id_status": "auth_metadata_missing",
"ingested": "2024-12-09T07:04:36Z",
"created": "2024-12-09T07:04:26.879Z",
"kind": "event",
"module": "netflow",
"action": "netflow_flow",
"category": [
"network"
],
"type": [
"connection"
],
"dataset": "netflow.log"
},
"device": {
"next_step": "SW Aggregator",
"name": "Internet Router"
},
"flow": {
"locality": "external",
"id": "5E4M1WfXYXw"
}
},
"fields": {
"event.ingested": [
"2024-12-09T07:04:36.000Z"
],
"@timestamp": [
"2024-12-09T07:04:26.879Z"
],
"event.created": [
"2024-12-09T07:04:26.879Z"
],
"netflow.exporter.timestamp": [
"2024-12-09T07:03:53.000Z"
]
}
}
{
"_index": ".ds-logs-netflow.log-default-2024.12.09-001458",
"_id": "pAE9qpMBV6TtyLZfAiAb",
"_version": 1,
"_score": 0,
"_source": {
"agent": {
"name": "logstash02",
"id": "82cca-0b9-4c5-ab7-72e68b",
"type": "filebeat",
"ephemeral_id": "1ce4-f3cb-401-a657-4c9d",
"version": "8.7.0"
},
"destination": {
"geo": {
"country_iso_code": "SA",
"timezone": "Asia/Riyadh",
"country_name": "Saudi Arabia",
"continent_code": "AS",
"location": {
"lon": 45,
"lat": 25
}
},
"port": 443,
"ip": "185.145.130.86",
"locality": "external"
},
"source": {
"geo": {
"region_iso_code": "SA-01",
"city_name": "Riyadh",
"country_iso_code": "SA",
"timezone": "Asia/Riyadh",
"country_name": "Saudi Arabia",
"continent_code": "AS",
"region_name": "Ar Riyāḑ",
"location": {
"lon": 6.752,
"lat": 4.637
}
},
"port": 2908,
"bytes": 3182,
"ip": "83.169.121.37",
"locality": "external",
"packets": 23
},
"fileset": {
"name": "log"
},
"network": {
"community_id": "1:KI5MzOuDociiuWaNV5cKd60pCFM=",
"bytes": 3182,
"transport": "tcp",
"type": "ipv4",
"iana_number": "6",
"packets": 23,
"direction": "external"
},
"tags": [
"forwarded",
"beats_input_raw_event",
"_geoip_database_unavailable_GeoLite2-ASN.mmdb",
"_geoip_database_unavailable_GeoLite2-ASN.mmdb"
],
"observer": {
"ip": "10.10.122.2"
},
"input": {
"type": "netflow"
},
"netflow": {
"packet_delta_count": 23,
"forwarding_status": 64,
"post_nat_destination_ipv4_address": "192.178.59.86",
"type": "netflow_flow",
"source_ipv4_address": "83.169.121.37",
"flow_end_reason": 3,
"exporter": {
"uptime_millis": 390195528,
"address": "10.10.122.2:3502",
"ip": "10.10.122.2",
"source_id": 2,
"version": 9,
"timestamp": "2024-12-09T07:09:10.000Z"
},
"post_packet_delta_count": 23,
"post_napt_source_transport_port": 0,
"post_ip_diff_serv_code_point": 0,
"destination_transport_port": 443,
"protocol_identifier": 6,
"post_octet_delta_count": 3182,
"flow_start_sys_up_time": 390063348,
"octet_delta_count": 3182,
"egress_interface": 91,
"post_napt_destination_transport_port": 443,
"application_id": [
20,
0,
0,
38,
58,
0,
0,
128,
160
],
"destination_ipv4_address": "185.145.130.86",
"post_ip_class_of_service": 0,
"ip_class_of_service": 0,
"post_nat_source_ipv4_address": "0.0.0.0",
"ingress_interface": 90,
"flow_end_sys_up_time": 390188838,
"source_transport_port": 2908
},
"@timestamp": "2024-12-09T07:05:39.531Z",
"related": {
"ip": [
"83.169.121.37",
"185.145.130.86"
]
},
"ecs": {
"version": "8.6.0"
},
"service": {
"type": "netflow"
},
"data_stream": {
"namespace": "default",
"type": "logs",
"dataset": "netflow.log"
},
"@version": "1",
"event": {
"duration": 125490000000,
"agent_id_status": "auth_metadata_missing",
"ingested": "2024-12-09T07:05:44Z",
"created": "2024-12-09T07:05:39.531Z",
"kind": "event",
"module": "netflow",
"start": "2024-12-09T07:05:39.531Z",
"action": "netflow_flow",
"end": "2024-12-09T07:09:03.310Z",
"category": [
"network"
],
"type": [
"connection"
],
"dataset": "netflow.log"
},
"device": {
"next_step": "WAF",
"name": "Perimeter FW"
},
"flow": {
"locality": "external",
"id": "NNAUJjIxvYI"
}
},
"fields": {
"event.end": [
"2024-12-09T07:09:03.310Z"
],
"event.ingested": [
"2024-12-09T07:05:44.000Z"
],
"@timestamp": [
"2024-12-09T07:05:39.531Z"
],
"event.start": [
"2024-12-09T07:05:39.531Z"
],
"event.created": [
"2024-12-09T07:05:39.531Z"
],
"netflow.exporter.timestamp": [
"2024-12-09T07:09:10.000Z"
]
}
}