# Logstash NFLOG input plugin should be useful

**URL:** <https://discuss.elastic.co/t/logstash-nflog-input-plugin-should-be-useful/21465>\
**Category:** Elasticsearch\
**Created:** [January 3, 2015, 7:50pm UTC](https://discuss.elastic.co/t/logstash-nflog-input-plugin-should-be-useful/21465 "2015-01-03T19:50:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_Depp](https://avatars.discourse-cdn.com/v4/letter/j/a587f6/32.png) [@John\_Depp](https://discuss.elastic.co/u/John_Depp)\
**Post date:** [January 3, 2015, 7:50pm UTC](https://discuss.elastic.co/t/logstash-nflog-input-plugin-should-be-useful/21465/1 "2015-01-03T19:50:29Z")

</div>

Hello everyone!

I'm trying to implement some traffic analysys with ELK.  
For now, I have 2 options to choose from (well, AFAIK):

- using plain logs with LOG iptables target;
- using plain logs with ULOG/NFLOG iptables target and ulogd2 daemon;
- using json logs with ULOG/NFLOG and ulogd2.  
The problem is, log files for traffic accounting are huge, and CPU load for  
combining ulogd+logstash(-forwarder) is considerable.  
To get rid of intermediate logs and agents, could we have an input plugin  
for NFLOG netfilter target?  
It should be pretty similar to tcp input plugin.  
There is a nflog gem, [http://rubygems.org/gems/nflog](http://rubygems.org/gems/nflog), libnetfilter\_log  
wrapper.

Thank you.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/08a4bc0c-d6d9-4e63-b1b7-8d8de6595bbd%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/08a4bc0c-d6d9-4e63-b1b7-8d8de6595bbd%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:41am UTC](https://discuss.elastic.co/t/logstash-nflog-input-plugin-should-be-useful/21465/2 "2017-07-06T00:41:01Z")

</div>


