The Logstash modules will take over your Logstash configuration, and cannot be setup in combination with other Pipelines. This is a known issue.
A few points that might be relevant for you:
The Logstash Netflow Module was originally based on ElastiFlow 1.0.0 and is quite dated at this point. You might want to consider using the latest release of ElastiFlow instead. You can see a comparison of the differences HERE. You will notice from the setup instructions that ElastiFlow is designed to be setup in pipelines.yml and fully supports running along side other pipelines. However...
Just because you can run ElastiFlow in a multi-pipeline setup. Network flow data can be very voluminous. This is easily underestimated. You will want to be certain that you have sufficient resources available to handle the amount of data you will collect. You might find it necessary to give Flow collection it own dedicated Logstash instance, tuned to the needs of high UDP ingest rates.
Great information! Thank you! I have decided to keep my elastiflow monitoring on it's own instance, as after a day of collecting logs from just one core I was pulling in 13GB of logs in one day.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.