# Filebeat netflow module do not start after update to 7.11

**URL:** <https://discuss.elastic.co/t/filebeat-netflow-module-do-not-start-after-update-to-7-11/264037>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 11, 2021, 4:42pm UTC](https://discuss.elastic.co/t/filebeat-netflow-module-do-not-start-after-update-to-7-11/264037 "2021-02-11T16:42:30Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![UweW](https://avatars.discourse-cdn.com/v4/letter/u/ed8c4c/32.png) [@UweW](https://discuss.elastic.co/u/UweW)\
**Post date:** [February 11, 2021, 4:42pm UTC](https://discuss.elastic.co/t/filebeat-netflow-module-do-not-start-after-update-to-7-11/264037/1 "2021-02-11T16:42:30Z")

</div>

Hi,  
after updating the stack from 7.10.2 to 7.11 the netflow module will not start anymore.  
The only message we see every 10 seconds in journal is

```auto
filebeat[1976620]: 2021-02-11T17:40:01.242+0100 ERROR [reload] cfgfile/list.go:99 Error creating runner from config: Error getting config for fileset netflow/log: Error interpreting the template of the input: template: text:8:5: executing "text" at <.internal_networks>: map has no entry for key "internal_networks"

```

Hoppe that sombody can help.

Best regards  
Uwe

---

<div class="post-metadata">

**Author:** ![UweW](https://avatars.discourse-cdn.com/v4/letter/u/ed8c4c/32.png) [@UweW](https://discuss.elastic.co/u/UweW)\
**Post date:** [February 11, 2021, 5:37pm UTC](https://discuss.elastic.co/t/filebeat-netflow-module-do-not-start-after-update-to-7-11/264037/2 "2021-02-11T17:37:15Z")

</div>

was able to fix it.  
With 7.11 the ../modules/netflow.yml changed

I had to add

```auto
      internal_networks:
        - private

```

in my existing yml file

---

<div class="post-metadata">

**Author:** ![abraxxa](https://avatars.discourse-cdn.com/v4/letter/a/8baadc/32.png) [@abraxxa](https://discuss.elastic.co/u/abraxxa)\
**Post date:** [February 18, 2021, 8:58am UTC](https://discuss.elastic.co/t/filebeat-netflow-module-do-not-start-after-update-to-7-11/264037/3 "2021-02-18T08:58:44Z")

</div>

Just had the same issue.  
The new variable is neither documented nor a note in the upgrade guide or breaking changes!

---

<div class="post-metadata">

**Author:** ![abraxxa](https://avatars.discourse-cdn.com/v4/letter/a/8baadc/32.png) [@abraxxa](https://discuss.elastic.co/u/abraxxa)\
**Post date:** [February 18, 2021, 9:28am UTC](https://discuss.elastic.co/t/filebeat-netflow-module-do-not-start-after-update-to-7-11/264037/4 "2021-02-18T09:28:55Z")

</div>

I opened a bug for the startup failure and missing docs for the new variable: [[filebeat][netflow] filebeat does't start when internal\_networks variable isn't defined in config file · Issue #24094 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/24094)

---

<div class="post-metadata">

**Author:** ![maxbaumgarten](https://avatars.discourse-cdn.com/v4/letter/m/c4cdca/32.png) [@maxbaumgarten](https://discuss.elastic.co/u/maxbaumgarten)\
**Post date:** [March 12, 2021, 3:50am UTC](https://discuss.elastic.co/t/filebeat-netflow-module-do-not-start-after-update-to-7-11/264037/5 "2021-03-12T03:50:17Z")

</div>

I'm running filebeat 7.11.2 in docker/docker-compose and am getting the same error still.

**Error:**

> 2021-03-12T03:38:31.569Z INFO [publisher] pipeline/module.go:113 Beat name: b0947ece6aad  
> 2021-03-12T03:38:31.571Z INFO beater/filebeat.go:117 Enabled modules/filesets: netflow (log), ()  
> 2021-03-12T03:38:31.571Z INFO instance/beat.go:437 filebeat stopped.  
> 2021-03-12T03:38:31.571Z ERROR instance/beat.go:971 Exiting: Error getting config for fileset netflow/log: Error interpreting the template of the input: template: text:8:5: executing "text" at \<.internal\_networks\>: map has no entry for key "internal\_networks"

Below are my configs:

**Docker-compose:**

```
filebeat:
image: docker.elastic.co/beats/filebeat:7.11.2
command: filebeat -e -strict.perms=false
volumes:
  - type: bind
    source: ./beats/filebeat.yml
    target: /usr/share/filebeat/filebeat.yml
    read_only: true
  - type: bind
    source: ./beats/netflow.yml
    target: /usr/share/filebeat/netflow.yml
    read_only: true
ports:
  - "2055:2055"
networks:
  - elk
depends_on:
  - elasticsearch

```

**filebeat.yml:**

```
filebeat.config.modules:
  enabled: true
  path: ${path.config}/modules.d/*.yml

filebeat.modules:
  - module: netflow

setup.template.enabled: true

output.elasticsearch:
  hosts: ["whatever:9200"]

```

**netflow.yml:**

```
- module: netflow
  log:
    enabled: true
    var:
      netflow_host: 0.0.0.0
      netflow_port: 2055
      # internal_networks specifies which networks are considered internal or private
      # you can specify either a CIDR block or any of the special named ranges listed
      # at: https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#condition-network
      internal_networks:
        - private

```

---

<div class="post-metadata">

**Author:** ![mayer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mayer/32/42164_2.png) [@mayer](https://discuss.elastic.co/u/mayer)\
**Post date:** [March 21, 2021, 9:59pm UTC](https://discuss.elastic.co/t/filebeat-netflow-module-do-not-start-after-update-to-7-11/264037/6 "2021-03-21T21:59:03Z")

</div>

Dear All,  
I have a similar issue. I upgraded from 7.10.2 to 7.11.2  
Netflow didn't work, but found this article and changed `/etc/filebeat/modules.d/netflow.yml`  
This is the content:

```
# Module: netflow
# Docs: https://www.elastic.co/guide/en/beats/filebeat/7.10/filebeat-module-netflow.html

- module: netflow
  log:
    enabled: true
    var:
      netflow_host: 0.0.0.0
      netflow_port: 2055
      internal_networks:
        - private

```

When I run `filebeat setup --modules netflow` I get this error

`Exiting: Error getting config for fileset netflow/log: Error interpreting the template of the input: template: text:8:5: executing "text" at <.internal_networks>: map has no entry for key "internal_networks"`

Any help is welcome.

Kind regards  
Hans

---

<div class="post-metadata">

**Author:** ![UweW](https://avatars.discourse-cdn.com/v4/letter/u/ed8c4c/32.png) [@UweW](https://discuss.elastic.co/u/UweW)\
**Post date:** [March 21, 2021, 10:35pm UTC](https://discuss.elastic.co/t/filebeat-netflow-module-do-not-start-after-update-to-7-11/264037/7 "2021-03-21T22:35:48Z")

</div>

@mayer , I am also on 7.11.2 but it is working. The only diffrence is that I use the interface adresse instead of 0.0.0.0

Best regards  
Uwe

---

<div class="post-metadata">

**Author:** ![mayer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mayer/32/42164_2.png) [@mayer](https://discuss.elastic.co/u/mayer)\
**Post date:** [March 22, 2021, 7:53am UTC](https://discuss.elastic.co/t/filebeat-netflow-module-do-not-start-after-update-to-7-11/264037/8 "2021-03-22T07:53:53Z")

</div>

Hi Uwe,

thanks coming back to my question. I tried your suggestion but it didn't help. But I have a workaround. I am not sure if good or bad, but it works. I restored the file `/usr/share/filebeat/module/netflow/log/config/netflow.yml` from my backup before the time of upgrade. And now it's working. This is the difference which was inserted in the last release:

```auto
7a8,14
> {{if .internal_networks}}
> internal_hosts:
> {{range .internal_networks}}
> - '{{ . }}'
> {{end}}
> {{end}}
> 

```

// Hans

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2021, 9:54am UTC](https://discuss.elastic.co/t/filebeat-netflow-module-do-not-start-after-update-to-7-11/264037/9 "2021-04-19T09:54:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
