Module: netflow
Docs: https://www.elastic.co/guide/en/beats/filebeat/main/filebeat-module-netflow.html
-
module: netflow
log:
enabled: true
var:
netflow_host: 10.74.192.64
netflow_port: 2055
tags: ["INQ"]
# internal_networks specifies which networks are considered internal or private
# you can specify either a CIDR block or any of the special named ranges listed
# at: Define processors | Filebeat Reference [8.12] | Elastic
internal_networks:
- private -
module: netflow
log:
enabled: true
var:
netflow_host: 10.74.192.64
netflow_port: 4444
tags: ["MEDLOG"]
# internal_networks specifies which networks are considered internal or private
# you can specify either a CIDR block or any of the special named ranges listed
# at: Define processors | Filebeat Reference [8.12] | Elastic
internal_networks:
- privat