# Fliebeat netflow vs elastiflow

**URL:** <https://discuss.elastic.co/t/fliebeat-netflow-vs-elastiflow/247114>\
**Category:** Kibana\
**Created:** [September 1, 2020, 3:17pm UTC](https://discuss.elastic.co/t/fliebeat-netflow-vs-elastiflow/247114 "2020-09-01T15:17:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![leostereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leostereo/32/74891_2.png) [@leostereo](https://discuss.elastic.co/u/leostereo)\
**Post date:** [September 1, 2020, 3:17pm UTC](https://discuss.elastic.co/t/fliebeat-netflow-vs-elastiflow/247114/1 "2020-09-01T15:17:46Z")

</div>

Hello , here im, trying to find a nice solution for netflow analisis.  
After reading elastiflow at  
[https://github.com/robcowart/elastiflow](https://github.com/robcowart/elastiflow)  
And testing my recently working filebeat netflow module can not find more than cosmetic differences.  
What Im looking for in the tool is:  
1 List top destination and source flow.  
2 Find strange behaviour on overall traffic (this can help me debug attacks).  
3 Create my own traffic graphs based on particular ip.

I think point 1 and 2 are very nice here at filebeat module.  
Point 3 is not very clear for me , I need to investigate a little bit more (im used to work with nfsen where you can create your own profiles ... this should be same here somehow).

Ok ... any feeling users would like to share would be wellcome.  
Leandro.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 2, 2020, 4:22am UTC](https://discuss.elastic.co/t/fliebeat-netflow-vs-elastiflow/247114/2 "2020-09-02T04:22:52Z")

</div>

Have you looked at the Elastic Security App there is all sorts of Network analysis... and there are some built in detection rules as well as anomaly detection.

[https://www.elastic.co/guide/en/kibana/current/xpack-siem.html](https://www.elastic.co/guide/en/kibana/current/xpack-siem.html)

Edit : oh and you can define your own detections as well.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 30, 2020, 4:22am UTC](https://discuss.elastic.co/t/fliebeat-netflow-vs-elastiflow/247114/3 "2020-09-30T04:22:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
