# Help with Netflow Configuration

**URL:** <https://discuss.elastic.co/t/help-with-netflow-configuration/79387>\
**Category:** Logstash\
**Created:** [March 21, 2017, 10:52am UTC](https://discuss.elastic.co/t/help-with-netflow-configuration/79387 "2017-03-21T10:52:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![BenoitJ76](https://avatars.discourse-cdn.com/v4/letter/b/74df32/32.png) [@BenoitJ76](https://discuss.elastic.co/u/BenoitJ76)\
**Post date:** [March 21, 2017, 10:52am UTC](https://discuss.elastic.co/t/help-with-netflow-configuration/79387/1 "2017-03-21T10:52:28Z")

</div>

Hello,

First, I have this error : "[2017-03-21T11:36:33,543][WARN][logstash.codecs.netflow] No matching template for flow id 260" I read a lot of topics about that but I don't know how to solve this.

Then, I tried to use the convert function but it didn't worked.

My config:

input {  
udp {  
port =\> 2055  
codec =\> netflow {  
versions =\> [9]  
netflow\_definitions =\> "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-codec-netflow-3.4.0/lib/logstash/codecs/netflow/netflow.yaml"  
}  
type =\> netflow  
tags =\> ["netflow"]  
}  
}

filter {  
mutate { convert =\> ["netflow.protocol" , "string"]  
}  
translate {  
field =\> "[netflow][protocol]"  
destination =\> "[netflow][protocol]"  
override =\> "true"  
dictionary =\> [ "6", "TCP",  
"17", "UDP",  
"1", "ICMP",  
"47", "GRE",  
"50", "ESP",  
"58", "IPv6-ICMP"  
]  
}

```
    }

```

output {  
if "netflow" in [tags] {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "logstash\_netflow9-%{+YYYY.MM.dd}"  
template\_name =\> "netflow"  
}

stdout { codec =\> rubydebug }  
}

}

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![dannygoulder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dannygoulder/32/22259_2.png) [@dannygoulder](https://discuss.elastic.co/u/dannygoulder)\
**Post date:** [March 21, 2017, 5:56pm UTC](https://discuss.elastic.co/t/help-with-netflow-configuration/79387/2 "2017-03-21T17:56:28Z")

</div>

Normally, you get that error when you first start sending netflow data to a newly-initialised Logstash instance.

This is because Netflow v9 is [template-based](http://www.cisco.com/c/en/us/td/docs/ios/12_0s/feature/guide/nfexpfv9.html#wp1069824).

Normally you just need to wait a little while and then this error will stop once the template appears in the stream, allowing the fields to be correctly decoded. You can check the config of your router or firewall to see how frequently the template is sent.

But if you are waiting for a while and still nothing, post some more info e.g. what logstash version you have, what version of the netflow codec plugin...

---

<div class="post-metadata">

**Author:** ![BenoitJ76](https://avatars.discourse-cdn.com/v4/letter/b/74df32/32.png) [@BenoitJ76](https://discuss.elastic.co/u/BenoitJ76)\
**Post date:** [March 22, 2017, 9:50am UTC](https://discuss.elastic.co/t/help-with-netflow-configuration/79387/3 "2017-03-22T09:50:30Z")

</div>

Okok for the error, I did not understand that it was normal but yes after a while I had already all my data.

However, regarding the mutate function, I want to use it to convert some field to string and use the tranlate function to display the name of the protocol according to the port. But I have an error specifying that my fields are number despite the mutate fuction:

filter {  
mutate { convert =\> ["netflow.protocol" , "string"]  
}  
translate {  
field =\> "[netflow][protocol]"  
destination =\> "[netflow][protocol]"  
override =\> "true"  
dictionary =\> [ "6", "TCP",  
"17", "UDP",  
"1", "ICMP",  
"47", "GRE",  
"50", "ESP",  
"58", "IPv6-ICMP"  
]  
}  
}

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [March 22, 2017, 12:47pm UTC](https://discuss.elastic.co/t/help-with-netflow-configuration/79387/4 "2017-03-22T12:47:47Z")

</div>

> [@BenoitJ76](#):
>
> mutate { convert =\> ["netflow.protocol" , "string"] }

Instead of _netflow.protocol_ try **[netflow][protocol]** in the mutate filter.

Rob

---

<div class="post-metadata">

**Author:** ![BenoitJ76](https://avatars.discourse-cdn.com/v4/letter/b/74df32/32.png) [@BenoitJ76](https://discuss.elastic.co/u/BenoitJ76)\
**Post date:** [March 22, 2017, 1:06pm UTC](https://discuss.elastic.co/t/help-with-netflow-configuration/79387/5 "2017-03-22T13:06:28Z")

</div>

Same error:

"[2017-03-22T14:04:26,683][WARN][logstash.outputs.elasticsearch] Failed action. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"logstash\_netflow9-2017.03.22", :\_type=\>"netflow", :\_routing=\>nil}, 2017-03-22T13:04:27.000Z IPADDRESS %{message}], :response=\>{"index"=\>{"\_index"=\>"logstash\_netflow9-2017.03.22", "\_type"=\>"netflow", "\_id"=\>"REDACTED", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse [netflow.protocol]", "caused\_by"=\>{"type"=\>"number\_format\_exception", "reason"=\>"For input string: "UDP""}}}}}"

Config:

filter {  
mutate { convert =\> { "[netflow][protocol]" =\> "string" }  
}  
translate {  
field =\> "[netflow][protocol]"  
destination =\> "[netflow][protocol]"  
override =\> "true"  
dictionary =\> [ "6", "TCP",  
"17", "UDP",  
"1", "ICMP",  
"47", "GRE",  
"50", "ESP",  
"58", "IPv6-ICMP"]  
}  
}

---

<div class="post-metadata">

**Author:** ![BenoitJ76](https://avatars.discourse-cdn.com/v4/letter/b/74df32/32.png) [@BenoitJ76](https://discuss.elastic.co/u/BenoitJ76)\
**Post date:** [March 22, 2017, 1:15pm UTC](https://discuss.elastic.co/t/help-with-netflow-configuration/79387/6 "2017-03-22T13:15:26Z")

</div>

Same too with mutate { convert =\> ["[netflow][protocol]", "string" ] }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2017, 1:15pm UTC](https://discuss.elastic.co/t/help-with-netflow-configuration/79387/7 "2017-04-19T13:15:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
