# How to use/have just one address field in Netflow module regardless of IP version?

**URL:** <https://discuss.elastic.co/t/how-to-use-have-just-one-address-field-in-netflow-module-regardless-of-ip-version/205519>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [October 28, 2019, 4:59pm UTC](https://discuss.elastic.co/t/how-to-use-have-just-one-address-field-in-netflow-module-regardless-of-ip-version/205519 "2019-10-28T16:59:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jorge\_Correa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jorge_correa/32/45613_2.png) [@Jorge\_Correa](https://discuss.elastic.co/u/Jorge_Correa)\
**Post date:** [October 28, 2019, 4:59pm UTC](https://discuss.elastic.co/t/how-to-use-have-just-one-address-field-in-netflow-module-regardless-of-ip-version/205519/1 "2019-10-28T16:59:44Z")

</div>

Hi! I was using the Logstash netflow module for a while. With ELK 7.4 I started to get some errors with UDP input and realized that Logstash Netflow Module was being deprecated. So, I installed Filebeat Netflow Module.

However I already have some visualizations and dashboards built using the Logstash Netflow Modules fields. So, I'm migrating them.

In Logstash Netflow Module and many other tools that work with Netflow the addresses fields are so simple, as src\_addr and dst\_addr. They exist just like this, regardless if the value is IPv4 or IPv6. This is a very common way and turns the filtering and visualizations easy.

But, with Filebeat Netflow Module we have netflow.destination\_ipv4\_address, netflow.source\_ipv4\_address, netflow.destination\_ipv6\_address and netflow.source\_ipv6\_address.

The segregation of v4 and v6 turns grouping tasks more complex because some flows will have the values empty. I'll have to had different searches and visualizations just to segregate v4 and v6.

Is there some way to have just src\_addr and dst\_addr fields, regardless of IP version?

Thank you!

EDIT 1:

I've realized there are fields named source.ip and destination.ip. However they only exist when the flow is v4. In v6 flows these fields doesn't exist. They could be used as the single address field in aggregations, but they aren't working for IPv6 flows.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 25, 2019, 4:59pm UTC](https://discuss.elastic.co/t/how-to-use-have-just-one-address-field-in-netflow-module-regardless-of-ip-version/205519/2 "2019-11-25T16:59:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
