Hi team, we have configured a Palo Alto Firewall to send Netflow to a Filebeat.
We are seeing all events right, except that the "User-ID" Netflow field (value 56702) its not shown.
We have replaced the Filebeat with a Logstash, and with it we are seeing the "User-ID" Netflow field is mapped on the "netflow_user_id" Elasticsearch field.
Is there any way to configure the Netflow Filebeat Input to collect it? Or it's an issue that must be fixed in the code?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.