Filebeat, elasticsearch, and Kibana are deployed in the same host.
Everything is running properly and the Netflow data was successfully visualized on Kibana.
But just curious about one thing, why the flow Exporters chart is showing that the flow source is only from filebeat agent?
I hope that the original flow source (network device IP/Hostname) should be counted and visualized.
any one can help?
The issue arises because the Netflow data as processed and stored in Elasticsearch attributes the data source to Filebeat, not the original network devices. To fix this, ensure the correct source fields are used in your Elasticsearch mappings and Kibana visualizations, and verify Filebeat's Netflow module configuration to ensure it's accurately capturing and forwarding the network devices' IP addresses or hostnames.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.