Filebeat multiple sources netflow module

Hello there,

My ELK Stack is composed by:
Elasticsearch
Kibana
Filebeat

My question is, how can I accomplish multiple sources (firewall) to send same port 2055 netflow module? Is possible? Or not?

Thanks in advance for the attention,

I am not sure I understand what you are trying to do. You want Filebeat to read from multiple netflow hosts/ports?

I got 5 firewalls which I need to send flows (All using the same port 2055/udp). I need to know if I can use only 1 filebeat as netflow module receptor or not.

thks.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.