I have installed ELK using docker 6.2.3.
I can see that standard netflow dashboard/visualisation use netflow.dst_addr but I don't have such field. I have: netflow.ipv4_dst_addr
netflow.bytes (dashboard) -> netflow.in_bytes (me)
What is the problem ?
I have found a solution.
I think that it should be here: https://www.elastic.co/guide/en/logstash/current/netflow-module.html
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.