# Netflow Codec Not Matching Interface from Netflow Export

**URL:** <https://discuss.elastic.co/t/netflow-codec-not-matching-interface-from-netflow-export/37864>\
**Category:** Logstash\
**Created:** [December 23, 2015, 2:48pm UTC](https://discuss.elastic.co/t/netflow-codec-not-matching-interface-from-netflow-export/37864 "2015-12-23T14:48:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stefano\_Pirrello](https://avatars.discourse-cdn.com/v4/letter/s/a88e4f/32.png) [@Stefano\_Pirrello](https://discuss.elastic.co/u/Stefano_Pirrello)\
**Post date:** [December 23, 2015, 2:48pm UTC](https://discuss.elastic.co/t/netflow-codec-not-matching-interface-from-netflow-export/37864/1 "2015-12-23T14:48:21Z")

</div>

Hi,

I've setup ELK for Netflow analysis and overall everything seems to be working fine. The only problem I'm seeing is the Netflow codec is not matching interface information of the router. For instance, I'm not seeing any hits for the indice I setup for ports Gig0/0.50 or Gi0/1 on my Cisco ISR 2911 router. Has anyone had any success with this?

I'm using the following codec found in Github.

> **[logstash-plugins/logstash-codec-netflow](https://github.com/logstash-plugins/logstash-codec-netflow)**
>
> Contribute to logstash-codec-netflow development by creating an account on GitHub.

Here's the template I setup for logstash.

'{  
"template" : "logstash\_netflow9-\*",  
"settings": {  
"index.refresh\_interval": "5s"  
},  
"mappings" : {  
"_default_" : {  
"\_all" : {"enabled" : false},  
"properties" : {  
"@version": { "index": "analyzed", "type": "integer" },  
"@timestamp": { "index": "analyzed", "type": "date" },  
"netflow": {  
"dynamic": true,  
"type": "object",  
"properties": {  
"version": { "index": "analyzed", "type": "integer" },  
"flow\_seq\_num": { "index": "not\_analyzed", "type": "long" },  
"engine\_type": { "index": "not\_analyzed", "type": "integer" },  
"engine\_id": { "index": "not\_analyzed", "type": "integer" },  
"sampling\_algorithm": { "index": "not\_analyzed", "type": "integer" },  
"sampling\_interval": { "index": "not\_analyzed", "type": "integer" },  
"flow\_records": { "index": "not\_analyzed", "type": "integer" },  
"if\_name": { "index": "analyzed", "type": "string" },  
"ipv4\_src\_addr": { "index": "analyzed", "type": "ip" },  
"ipv4\_dst\_addr": { "index": "analyzed", "type": "ip" },  
"ipv4\_next\_hop": { "index": "analyzed", "type": "ip" },  
"input\_snmp": { "index": "not\_analyzed", "type": "long" },  
"output\_snmp": { "index": "not\_analyzed", "type": "long" },  
"in\_pkts": { "index": "analyzed", "type": "long" },  
"out\_pkts": { "index": "analyzed", "type": "long" },  
"in\_bytes": { "index": "analyzed", "type": "long" },  
"out\_bytes": { "index": "analyzed", "type": "long" },  
"first\_switched": { "index": "not\_analyzed", "type": "date" },  
"last\_switched": { "index": "not\_analyzed", "type": "date" },  
"l4\_src\_port": { "index": "analyzed", "type": "long" },  
"l4\_dst\_port": { "index": "analyzed", "type": "long" },  
"tcp\_flags": { "index": "analyzed", "type": "integer" },  
"protocol": { "index": "analyzed", "type": "integer" },  
"src\_tos": { "index": "analyzed", "type": "integer" },  
"src\_as": { "index": "analyzed", "type": "integer" },  
"dst\_as": { "index": "analyzed", "type": "integer" },  
"src\_mask": { "index": "analyzed", "type": "integer" },  
"dst\_mask": { "index": "analyzed", "type": "integer" }  
}  
}  
}  
}  
}  
}'

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 23, 2015, 10:31pm UTC](https://discuss.elastic.co/t/netflow-codec-not-matching-interface-from-netflow-export/37864/2 "2015-12-23T22:31:53Z")

</div>

I don't know netflow very well, but are you using a compatible version? We only [support](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-netflow.html) v5 and v9.

---

<div class="post-metadata">

**Author:** ![Stefano\_Pirrello](https://avatars.discourse-cdn.com/v4/letter/s/a88e4f/32.png) [@Stefano\_Pirrello](https://discuss.elastic.co/u/Stefano_Pirrello)\
**Post date:** [December 24, 2015, 4:14am UTC](https://discuss.elastic.co/t/netflow-codec-not-matching-interface-from-netflow-export/37864/3 "2015-12-24T04:14:58Z")

</div>

I'm using Netflow V9.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:17am UTC](https://discuss.elastic.co/t/netflow-codec-not-matching-interface-from-netflow-export/37864/4 "2017-07-06T05:17:24Z")

</div>


