# How do I run netflow setup when using elasticsearch as config store in Azure?

**URL:** <https://discuss.elastic.co/t/how-do-i-run-netflow-setup-when-using-elasticsearch-as-config-store-in-azure/201070>\
**Category:** Logstash\
**Created:** [September 25, 2019, 2:36pm UTC](https://discuss.elastic.co/t/how-do-i-run-netflow-setup-when-using-elasticsearch-as-config-store-in-azure/201070 "2019-09-25T14:36:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![wmassingham](https://avatars.discourse-cdn.com/v4/letter/w/e36b37/32.png) [@wmassingham](https://discuss.elastic.co/u/wmassingham)\
**Post date:** [September 25, 2019, 2:36pm UTC](https://discuss.elastic.co/t/how-do-i-run-netflow-setup-when-using-elasticsearch-as-config-store-in-azure/201070/1 "2019-09-25T14:36:26Z")

</div>

I'm trying to get netflow set up for the SIEM tools in my Azure instance. I have data coming into ES through a logstash pipeline (summarized here):

```
input {
  udp {
    port => 2055
    codec => netflow
    type => netflow                                                                                                                                   
  }
}
output {
    if [type] == "netflow" {
        elasticsearch {
			hosts => ["${ELASTICSEARCH_URL}"]
			user => "logstash_pipeline"
			password => "<password>"
			index => "netflow-%{+YYYY.MM.dd}"
		}
    }
}

```

But when I go into the SIEM page, it prompts me to view setup instructions. So I pick Netflow. I tried adding the `modules` section as follows to logstash.yml:

```
modules:
  - name: netflow
    var.input.udp.port: 2055
    var.elasticsearch.hosts: ["${ELASTICSEARCH_URL}"]
    var.elasticsearch.username: elastic
    var.elasticsearch.password: <password>

```

But logstash refused to start, saying "java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit"

So I removed that and just tried running `/usr/share/logstash/bin/logstash --modules netflow --setup`, but logstash then says "ERROR: You cannot use --modules since Elasticsearch is configured as the config store".

So, how do I get Kibana to recognize this data for SIEM? How do I import the visualizations?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2019, 2:46pm UTC](https://discuss.elastic.co/t/how-do-i-run-netflow-setup-when-using-elasticsearch-as-config-store-in-azure/201070/2 "2019-10-23T14:46:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
