# Netflow Exporters only from Filebeat Host

**URL:** <https://discuss.elastic.co/t/netflow-exporters-only-from-filebeat-host/355712>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 19, 2024, 10:36am UTC](https://discuss.elastic.co/t/netflow-exporters-only-from-filebeat-host/355712 "2024-03-19T10:36:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yusran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yusran/32/123408_2.png) [@Yusran](https://discuss.elastic.co/u/Yusran)\
**Post date:** [March 19, 2024, 10:36am UTC](https://discuss.elastic.co/t/netflow-exporters-only-from-filebeat-host/355712/1 "2024-03-19T10:36:01Z")

</div>

Hi Team,

I just finished to Deploy Elastic Stack to Visualize Netflow data from several network devices, with the following deployment:

Network devices -\> Filebeat (Netflow Module) -\> Elasticsearch -\> Kibana.

Filebeat, elasticsearch, and Kibana are deployed in the same host.

Everything is running properly and the Netflow data was successfully visualized on Kibana.  
But just curious about one thing, why the **flow Exporters** chart is showing that the flow source is only from filebeat agent?  
I hope that the original flow source (network device IP/Hostname) should be counted and visualized.  
any one can help?

---

<div class="post-metadata">

**Author:** ![rtwolfe94022](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rtwolfe94022/32/132253_2.png) [@rtwolfe94022](https://discuss.elastic.co/u/rtwolfe94022)\
**Post date:** [March 20, 2024, 4:16am UTC](https://discuss.elastic.co/t/netflow-exporters-only-from-filebeat-host/355712/2 "2024-03-20T04:16:07Z")

</div>

The issue arises because the Netflow data as processed and stored in Elasticsearch attributes the data source to Filebeat, not the original network devices. To fix this, ensure the correct source fields are used in your Elasticsearch mappings and Kibana visualizations, and verify Filebeat's Netflow module configuration to ensure it's accurately capturing and forwarding the network devices' IP addresses or hostnames.

---

<div class="post-metadata">

**Author:** ![Yusran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yusran/32/123408_2.png) [@Yusran](https://discuss.elastic.co/u/Yusran)\
**Post date:** [March 26, 2024, 2:54am UTC](https://discuss.elastic.co/t/netflow-exporters-only-from-filebeat-host/355712/3 "2024-03-26T02:54:10Z")

</div>

could you please the setting that need configure properly?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 23, 2024, 4:54am UTC](https://discuss.elastic.co/t/netflow-exporters-only-from-filebeat-host/355712/4 "2024-04-23T04:54:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
