# Internal\_networks setting for netflow integration

**URL:** <https://discuss.elastic.co/t/internal-networks-setting-for-netflow-integration/327586>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [March 13, 2023, 6:36pm UTC](https://discuss.elastic.co/t/internal-networks-setting-for-netflow-integration/327586 "2023-03-13T18:36:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andres\_Altamirano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres_altamirano/32/94143_2.png) [@Andres\_Altamirano](https://discuss.elastic.co/u/Andres_Altamirano)\
**Post date:** [March 13, 2023, 6:36pm UTC](https://discuss.elastic.co/t/internal-networks-setting-for-netflow-integration/327586/1 "2023-03-13T18:36:47Z")

</div>

Hi,

I'm trying to replace filebeat netflow module with elastic integration "netflow" that is deployed on a policy running on a few servers.

Flows are indexed properly, but there is no way to set the `internal_networks` parameter to allow the network direction field to be set.

In filebeat, we can set that as a config for netflow module, but as an integration in fleet there is no parameter called internal\_networks.

I tried setting that parameter in the textbox called "Custom definitions", but that is not intended for that purpose and the agent failed starting.

How can we do this? Any docs?

Regards,  
Andres.

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [March 22, 2023, 9:09am UTC](https://discuss.elastic.co/t/internal-networks-setting-for-netflow-integration/327586/2 "2023-03-22T09:09:36Z")

</div>

Hey @Andres_Altamirano - thanks for flagging this. We've just merged a PR to add the internal\_networks parameter to the Netflow integration. You should see an update available (to v2.6) to the integration, which will expose the parameter.

> <https://github.com/elastic/integrations/issues/5620#event-8813945085>
>
> Our Filebeat Netflow module includes an option called \`internal\_network\` with th…e following description:
> 
> \_A list of CIDR ranges describing the IP addresses that you consider internal. This is used in determining the values of source.locality, destination.locality, and flow.locality. The values can be either a CIDR value or one of the named ranges supported by the \[network\](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#condition-network) condition. The default value is \[private\] which classifies RFC 1918 (IPv4) and RFC 4193 (IPv6) addresses as internal.\_
> 
> The Netflow integration does not include this option, which is preventing users from being able to set the network direction. Can we add this setting to the integration?
> 
> Relevant discuss issue: https://discuss.elastic.co/t/internal-networks-setting-for-netflow-integration/327586

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2023, 9:09am UTC](https://discuss.elastic.co/t/internal-networks-setting-for-netflow-integration/327586/3 "2023-04-19T09:09:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
