Hi all, very new to ES and i started writing my own logging function writing direct to Elasticsearch with C# to log network packet counters on a minute basis (IP pairs, bytes in/out), and run a query by sum over multiple daily time indices, this would be for bandwidth accounting (to run on a specific day, and get the data-in and data-out bandwidth for the past calendar month for a specific IP).
I then saw Logstash with Netflow input which would be a lot more appropriate and would give details such as protocol and countries and a Kabana dash to search with, I can get that setup, but is it possible to write an integration to query the data store (es?) for the monthly bandwidth as above, or some form of filter to output daily bandwidth in/out per IP to a file or database?
Ideally i would like my external app to query on a scheduled basis and pull out this data which would form part of the billing system.
Are there specific schema or API that i could start with?