# LogStash & Netflow : Wrong values?

**URL:** <https://discuss.elastic.co/t/logstash-netflow-wrong-values/126890>\
**Category:** Logstash\
**Created:** [April 5, 2018, 9:34am UTC](https://discuss.elastic.co/t/logstash-netflow-wrong-values/126890 "2018-04-05T09:34:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Julzor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julzor/32/43931_2.png) [@Julzor](https://discuss.elastic.co/u/Julzor)\
**Post date:** [April 5, 2018, 9:34am UTC](https://discuss.elastic.co/t/logstash-netflow-wrong-values/126890/1 "2018-04-05T09:34:13Z")

</div>

Hi,

I deployed a LogStash server dedicated to collecting Netflow flows (16 CPU).

The Netflow codec is working, i can see all my datas in the predifined dashboards in Kibana, and i also can graph' it on Grafana.

Everything looks good, except that when i aggregate the data of Netflow to see the bandwithd utilization i have a gap between what ElasticSearch returns me and the reality.

For example, if the graph' of the bandwidth that i got from SNMP (which represents the real value) show that the download/upload is 1.5Gbps/400Mbps during a specific time, the graph' based on Netflow data will maybe show 900Mbps/250Mbps.

The trend however is exactly the same, as well and the bursts that i can see of both graph'...

It's weird, i triple-checked my calculation formula (Netflow returns bytes count per minute, so i have to calculate the Bandwidth by using \_value/60\*8 to get bits/sec).

Has anyone encountered the same issue?

I have an average of 12k flows per seconds, but the server looks like it can handle it with 16 CPU.  
Is there any way to see if it dropps some flows?

Any advices would be appreciated.

---

<div class="post-metadata">

**Author:** ![solidz](https://avatars.discourse-cdn.com/v4/letter/s/bbe5ce/32.png) [@solidz](https://discuss.elastic.co/u/solidz)\
**Post date:** [April 8, 2018, 1:35pm UTC](https://discuss.elastic.co/t/logstash-netflow-wrong-values/126890/2 "2018-04-08T13:35:30Z")

</div>

Hi,

Netflow V9 ?  
Do you have the _last\_switched_ field on your netflow metric ? If yes, could you try to edit _@timestamp_ value with the _last\_switched_ field value ?

---

<div class="post-metadata">

**Author:** ![Julzor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julzor/32/43931_2.png) [@Julzor](https://discuss.elastic.co/u/Julzor)\
**Post date:** [April 9, 2018, 6:07am UTC](https://discuss.elastic.co/t/logstash-netflow-wrong-values/126890/3 "2018-04-09T06:07:27Z")

</div>

Hi,

Thank you for your reply.

Yes, this is Netflow V9.

I will look into the field you mentionned, however i made another post because i discovered that my Netflow LogStash node might drop some UDP packets 🙂

> [@Netflow Codec : UDP receive errors](https://discuss.elastic.co/t/netflow-codec-udp-receive-errors/127111):
>
> Hi, I have installed LogStash with the Netflow module to catch my flows and output them in ES and it works great, i can see my stats in Kibana without problems. I have between 5k and 12k flows/sec depending of the time of the day. A dedicated VM is doing the job with 16 CPU and 8G RAM, but i can see in Netstat that i have a lot of receiving errors : Udp: 1146481 packets received 89 packets to unknown port received. 59566 packet receive errors 475 packets sent 59566 receive buffer errors …

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2018, 6:15am UTC](https://discuss.elastic.co/t/logstash-netflow-wrong-values/126890/4 "2018-05-07T06:15:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
