# Logstash 6.2.4 netflow module no packets no bytes

**URL:** <https://discuss.elastic.co/t/logstash-6-2-4-netflow-module-no-packets-no-bytes/129936>\
**Category:** Logstash\
**Created:** [April 29, 2018, 12:23am UTC](https://discuss.elastic.co/t/logstash-6-2-4-netflow-module-no-packets-no-bytes/129936 "2018-04-29T00:23:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dalamar666](https://avatars.discourse-cdn.com/v4/letter/d/e9bcb4/32.png) [@dalamar666](https://discuss.elastic.co/u/dalamar666)\
**Post date:** [April 29, 2018, 12:23am UTC](https://discuss.elastic.co/t/logstash-6-2-4-netflow-module-no-packets-no-bytes/129936/1 "2018-04-29T00:23:47Z")

</div>

Hi,

I am running an ELK stack 6.2 on Ubuntu 16.04. I have netflow configured on my cisco ASA 5515 to come to the server. I can see from tshark that the packets are coming. When I debug logstash I can see it is getting the data. But when I go to Kibana and look at any of the dashboards, I am not getting bytes or packets. I get flow counts, cities, destination IP, source IP etc. I have another product on a windows machine gathering the data from the ASA and it goes through perfectly and shows me the bytes and everything. What am I missing?

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [April 29, 2018, 11:26am UTC](https://discuss.elastic.co/t/logstash-6-2-4-netflow-module-no-packets-no-bytes/129936/2 "2018-04-29T11:26:19Z")

</div>

You should use ElastiFlow...

> **[robcowart/elastiflow](https://github.com/robcowart/elastiflow)**
>
> elastiflow - Network flow Monitoring (Netflow, sFlow and IPFIX) with the Elastic Stack

The Logstash Netflow module was based on ElastiFlow v1.0.0 and is quite dated. Currently ElastiFlow is at [v2.1.0](https://github.com/robcowart/elastiflow/releases/tag/v2.1.0) and includes A LOT more functionality. Most important in your case is support for ASA bi-directional flows. This is most likely the reason you don't get bytes and packets.

Rob

Robert Cowart ([rob@koiossian.com](mailto:rob@koiossian.com))  
[www.koiossian.com](http://www.koiossian.com)  
True Turnkey SOLUTIONS for the Elastic Stack

---

<div class="post-metadata">

**Author:** ![dalamar666](https://avatars.discourse-cdn.com/v4/letter/d/e9bcb4/32.png) [@dalamar666](https://discuss.elastic.co/u/dalamar666)\
**Post date:** [April 30, 2018, 12:34pm UTC](https://discuss.elastic.co/t/logstash-6-2-4-netflow-module-no-packets-no-bytes/129936/3 "2018-04-30T12:34:23Z")

</div>

Rob,

I am trying to get the ElastiFlow working. I figured I would see what I could get with netflow in the mean time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 28, 2018, 12:34pm UTC](https://discuss.elastic.co/t/logstash-6-2-4-netflow-module-no-packets-no-bytes/129936/4 "2018-05-28T12:34:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
