I configured logstash to parse netflow, opened port 9995 and restarted the service.
I can see the data coming in via TCPDUMP however I do not see it in ES after the first ingest which I find kind of head scratching.
I'm new to this stack so I am having a hard time figuring out where to start troubleshooting. I don't see anything in the logs.
If anyone can get me started, I'd appreciate it.
It's logstash 3.x, everything was installed via YUM