@spalger yes thats what it looks like.
I'm intrested in netflow.ipv4_src_addr, netflow.ipv4_dst_addr and netflow.in_bytes
{
"_index": "netflow-2016.12.23",
"_type": "netflow",
"_id": "AVkq4HlGRFxRys8jOYJN",
"_score": null,
"_source": {
"netflow": {
"ipv4_src_host": "192.168.0.51",
"in_pkts": 3,
"first_switched": "2016-12-23T08:47:52.999Z",
"flowset_id": 256,
"l4_src_port": 56054,
"ipv4_next_hop": "x.x.128.1",
"ipv4_dst_host": "edge-z-m-mini-shv-01-amt2.facebook.com",
"in_bytes": 156,
"protocol": 6,
"tcp_flags": 17,
"xlate_src_addr_ipv4": "192.168.0.51",
"l4_dst_port": 443,
"output_snmp": 15,
"out_src_mac": "e4:8d:8c:20:ed:e2",
"dst_mask": 0,
"xlate_src_port": 0,
"ipv4_dst_addr": "31.13.64.36",
"src_tos": 0,
"in_dst_mac": "xx:xx:xx:20:ed:e6",
"src_mask": 0,
"xlate_dst_port": 0,
"version": 9,
"flow_seq_num": 29029,
"ipv4_src_addr": "192.168.0.51",
"last_switched": "2016-12-23T08:48:04.999Z",
"input_snmp": 13,
"xlate_dst_addr_ipv4": "31.13.64.36",
"protocol_name": "TCP"
},
"dst_geoip": {
"timezone": "Europe/Dublin",
"ip": "31.13.64.36",
"latitude": 53.3472,
"country_code2": "IE",
"country_name": "Ireland",
"continent_code": "EU",
"country_code3": "IE",
"location": [
-6.2439,
53.3472
],
"longitude": -6.2439
},
"@timestamp": "2016-12-23T08:48:20.000Z",
"@version": "1",
"host": "192.168.0.1",
"src_geoip": {},
"type": "netflow",
"tags": [
"netflow",
"_geoip_lookup_failure"
]
},
"fields": {
"netflow.first_switched": [
1482482872999
],
"netflow.last_switched": [
1482482884999
],
"@timestamp": [
1482482900000
]
},
"sort": [
1482482900000
]
}