# Filebeat: support for multiple identical fields in IPFIX/Netflow

**URL:** <https://discuss.elastic.co/t/filebeat-support-for-multiple-identical-fields-in-ipfix-netflow/364816>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 13, 2024, 6:55am UTC](https://discuss.elastic.co/t/filebeat-support-for-multiple-identical-fields-in-ipfix-netflow/364816 "2024-08-13T06:55:38Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![shanavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanavas/32/123224_2.png) [@shanavas](https://discuss.elastic.co/u/shanavas)\
**Post date:** [August 13, 2024, 6:55am UTC](https://discuss.elastic.co/t/filebeat-support-for-multiple-identical-fields-in-ipfix-netflow/364816/1 "2024-08-13T06:55:38Z")

</div>

Hello,

I am using filebeat to collect Netflow/IPFIX stream.  
When IPFIX template specifies the same information element (IE) multiple times, filebeat yields only the last value. I am wondering if filebeat can handle it.

Another tool [GitHub - CESNET/ipfixcol2: High-performance NetFlow v5/v9 and IPFIX collector (RFC7011)](https://github.com/CESNET/ipfixcol2) handles it by yielding an array for that IE.

The IPFIX template looks like this. Note the fields 71 and 17 are repeated.

 ![Screenshot 2024-08-13 at 11.53.12](https://us1.discourse-cdn.com/elastic/original/3X/0/5/059a398dcab0f862e3d3ade751db8aeba146c732.png)
