I am using elk stack for log monitoring and visualization.
Now I am monitoring pfsense and freenas with collectd which ships logs to logstash and after that it goes to elasticsearch, every thing works perfect Except the traffic graphs.
In kibana when I searching for the particular interface for if_octects or if_packets it shows me the constant value which is the higher one in rx and tx columns, and because of that my visualization for the bandwidth is not perfect.
It seems that the rx and tx values for if_octets or if_packets are not resetting, it stuck to the higher value only even if the no traffice is passing trough the interfaces.
Can any one let me know what I am doing wrong and where, is it in collectd config or something with logstash or kibana ?