Trying to test this project: https://github.com/robcowart/elastiflow
Issue: When running logstash version 6.2.2, enabling ipv6 fails but when i enable with version 5.6.8 it passes and pumps data to elasticsearch. Not sure is this is logstash issue or a plugins issue.
failing logstash host v6.2.2
:
[root@localhost conf.d]# /usr/share/logstash/bin/logstash-plugin list --verbose | grep flow
logstash-codec-netflow (3.11.2)
logstash-codec-sflow (2.0.2)
[root@localhost conf.d]# /usr/share/logstash/bin/logstash --version
logstash 6.2.2
Logs i receive from the failing logstash host /var/log/logstash/logstash-plain.log
: link
###################
working logstash host 5.6.8
:
[root@elastiflow-lab ~]# /usr/share/logstash/bin/logstash-plugin list --verbose | grep flow
logstash-codec-netflow (3.11.2)
logstash-codec-sflow (2.0.2)
[root@elastiflow-lab ~]# /usr/share/logstash/bin/logstash --version
logstash 5.6.8
Logs i receive from the working logstash host /var/log/logstash/logstash-plain.log
: link
###################
inputs that i use for both logstash hosts:
input {
# Netflow
udp {
id => "input_udp_netflow6"
host => "${ELASTIFLOW_NETFLOW_HOST6:[::1]}"
port => "${ELASTIFLOW_NETFLOW_PORT:2055}"
codec => netflow {
versions => [5,9]
}
type => "netflow"
}
# sFlow
udp {
id => "input_udp_sflow6"
host => "${ELASTIFLOW_SFLOW_HOST6:[::1]}"
port => "${ELASTIFLOW_SFLOW_PORT:6343}"
codec => sflow { }
type => "sflow"
}
# IPFIX
tcp {
id => "input_tcp_ipfix6"
host => "${ELASTIFLOW_IPFIX_TCP_HOST6:[::1]}"
port => "${ELASTIFLOW_IPFIX_TCP_PORT:4739}"
codec => netflow {
versions => [10]
target => "ipfix"
}
type => "ipfix"
}
udp {
id => "input_udp_ipfix6"
host => "${ELASTIFLOW_IPFIX_UDP_HOST6:[::1]}"
port => "${ELASTIFLOW_IPFIX_UDP_PORT:4739}"
codec => netflow {
versions => [10]
target => "ipfix"
}
type => "ipfix"
}
}
Any input would be appreciated.
Thank you,
dave