# Netflow Logstash V9 not working not getting any logs

**URL:** <https://discuss.elastic.co/t/netflow-logstash-v9-not-working-not-getting-any-logs/91228>\
**Category:** Logstash\
**Created:** [June 29, 2017, 6:59am UTC](https://discuss.elastic.co/t/netflow-logstash-v9-not-working-not-getting-any-logs/91228 "2017-06-29T06:59:14Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [June 29, 2017, 6:59am UTC](https://discuss.elastic.co/t/netflow-logstash-v9-not-working-not-getting-any-logs/91228/1 "2017-06-29T06:59:14Z")

</div>

Hallo Guys,

i face a really weird issue. I cannot get any netflow logs into logstash. They even dont show up on stdout. i can see with tcpdump dst port 1535 that there are logs incoming. With tcpdump dst port 1535 -A i also see that there is a message block, but it's not readable, on the host. When I start the docker container with -it and bash inside, i can also get the tcpdump dst port 1535 with the same output.

That is the last message in logstash.:  
06:26:09.143 [[main]\<udp] INFO logstash.inputs.udp - UDP listener started {:address=\>"localhost:1535", :receive\_buffer\_bytes=\>"106496", :queue\_size=\>"2000"}

i have no idea how I can solve this issue? Can you help me?

08:58:07.037483 IP netflowsender.53980 \> logstashserver.1535: UDP, length 596  
E..pA.@.?...  
c..  
b.  
.....+k.  
.TYT...7.........D.....  
`.p......*#................................................................*#`.p..............................................................  
c.K..........................................................................  
c.K..............................................................  
c....  
`...5................................................E...E.......`...5  
c....................................................E...E.......  
`.p......#*................ o.................. 3....... ..E...E...........#*`.p..................................................E...E..

Config File.:

input {  
udp {  
host =\> localhost  
port =\> 1535  
codec =\> netflow {  
versions =\> [9]  
netflow\_definitions =\> "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-codec-netflow-3.4.0/lib/logstash/codecs/netflow/netflow.yaml"  
}  
type =\> netflow  
}  
udp {  
host =\> localhost  
port =\> 1536  
codec =\> netflow {  
versions =\> [10]  
target =\> ipfix  
}  
type =\> ipfix  
}  
tcp {  
host =\> localhost  
port =\> 4739  
codec =\> netflow {  
versions =\> [10]  
target =\> ipfix  
}  
type =\> ipfix  
}  
}

output {  
stdout { codec =\> rubydebug }  
gelf {  
host =\> 'graylog'  
port =\> 12202  
}  
}

Logstash Version: 5.4.2 running on Docker in Debian.

---

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [June 29, 2017, 11:09am UTC](https://discuss.elastic.co/t/netflow-logstash-v9-not-working-not-getting-any-logs/91228/2 "2017-06-29T11:09:06Z")

</div>

Change

> host -\> "locahost"

To

> host =\> "your\_IP\_address"

And config flow point to : your\_IP\_address:1535

---

<div class="post-metadata">

**Author:** ![jorritfolmer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jorritfolmer/32/20327_2.png) [@jorritfolmer](https://discuss.elastic.co/u/jorritfolmer)\
**Post date:** [June 29, 2017, 11:32am UTC](https://discuss.elastic.co/t/netflow-logstash-v9-not-working-not-getting-any-logs/91228/3 "2017-06-29T11:32:32Z")

</div>

Can you send me a .pcap of your Netflow traffic so I can take a look at it?

---

<div class="post-metadata">

**Author:** ![jorritfolmer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jorritfolmer/32/20327_2.png) [@jorritfolmer](https://discuss.elastic.co/u/jorritfolmer)\
**Post date:** [June 29, 2017, 11:40am UTC](https://discuss.elastic.co/t/netflow-logstash-v9-not-working-not-getting-any-logs/91228/4 "2017-06-29T11:40:38Z")

</div>

Also, that device(s) are you exporting from?

---

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [June 29, 2017, 11:48am UTC](https://discuss.elastic.co/t/netflow-logstash-v9-not-working-not-getting-any-logs/91228/5 "2017-06-29T11:48:02Z")

</div>

input {  
udp {  
host =\> 10.98.241.10  
port =\> 1535  
codec =\> netflow {  
versions =\> [9]  
netflow\_definitions =\> "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-codec-netflow-3.4.0/lib/logstash/codecs/netflow/netflow.yaml"  
}  
type =\> netflow  
}  
udp {  
host =\> localhost  
port =\> 1536  
codec =\> netflow {  
versions =\> [10]  
target =\> ipfix  
}  
type =\> ipfix  
}  
tcp {  
host =\> localhost  
port =\> 4739  
codec =\> netflow {  
versions =\> [10]  
target =\> ipfix  
}  
type =\> ipfix  
}  
}

output {  
stdout { codec =\> rubydebug }  
gelf {  
host =\> 'graylog'  
port =\> 12202  
}  
}

sorry i don't know what "config flow point" exactly is?

---

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [June 29, 2017, 11:53am UTC](https://discuss.elastic.co/t/netflow-logstash-v9-not-working-not-getting-any-logs/91228/6 "2017-06-29T11:53:50Z")

</div>

Barracuda Firewalls. Of course i can give you a pcap.  
pcap.: [https://www.dropbox.com/s/ck2x020c4d08zm3/tcpdump.pcap?dl=0](https://www.dropbox.com/s/ck2x020c4d08zm3/tcpdump.pcap?dl=0)

The funny thing is, that i even don't see anything on "stdout" even with --debug on. I don't see anything being dropped, or not saved into. We need logstash to accept the netflow v9, since graylog cannot deal with it.

---

<div class="post-metadata">

**Author:** ![jorritfolmer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jorritfolmer/32/20327_2.png) [@jorritfolmer](https://discuss.elastic.co/u/jorritfolmer)\
**Post date:** [June 29, 2017, 12:13pm UTC](https://discuss.elastic.co/t/netflow-logstash-v9-not-working-not-getting-any-logs/91228/7 "2017-06-29T12:13:07Z")

</div>

Ah looks like it is actually IPFIX traffic, so you should either have the Barracuda's export it to your 4739 port, or change the logstash ports around.

Could you let the tcpdump run for a minute or two? Because your pcap doesn't contain any template packets that are needed to decode the data packets.

I'm guessing this is non-production data? If so is it ok if I include a sample from your new pcap in our rspec tests over at [github.com/logstash-plugins/logstash-codec-netflow](http://github.com/logstash-plugins/logstash-codec-netflow)? This helps expand our known-working library of netflow exporters against which we test every release.

---

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [June 29, 2017, 2:05pm UTC](https://discuss.elastic.co/t/netflow-logstash-v9-not-working-not-getting-any-logs/91228/8 "2017-06-29T14:05:03Z")

</div>

i changed the input in the config file.

here you go for the pcap.. [https://www.dropbox.com/s/vu4gxlxlv6hgm1a/tcpdumpnonprod.pcap?dl=0](https://www.dropbox.com/s/vu4gxlxlv6hgm1a/tcpdumpnonprod.pcap?dl=0) if it aint enough just tell me. You can add it to github. I searched for a folder where i can put it in. Sadly i didn't found one. I would have loved to contribute 😉

still in the logs i dont see any output to stdout  
15:55:17.292 [[main]-pipeline-manager] INFO logstash.inputs.tcp - Starting tcp input listener {:address=\>"localhost:4739"}  
15:55:17.315 [[main]-pipeline-manager] INFO logstash.pipeline - Pipeline main started  
15:55:17.322 [[main]\<udp] INFO logstash.inputs.udp - Starting UDP listener {:address=\>"localhost:1535"}  
15:55:17.347 [[main]\<udp] INFO logstash.inputs.udp - UDP listener started {:address=\>"localhost:1535", :receive\_buffer\_bytes=\>"106496", :queue\_size=\>"2000"}  
15:55:17.371 [Api Webserver] INFO logstash.agent - Successfully started Logstash API endpoint {:port=\>9600}

I can change the IPFIX Template that Barracuda is sending to "Default / Extended UniFlow" it is currently set on "Default without Barracuda Custom Fields and UniFlow". I also can change the "Byte order for data" to little or Big Endian.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b54b3ca7c6e55195dc786798e9bbf1f36d8196ae.png)

---

<div class="post-metadata">

**Author:** ![jorritfolmer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jorritfolmer/32/20327_2.png) [@jorritfolmer](https://discuss.elastic.co/u/jorritfolmer)\
**Post date:** [June 29, 2017, 3:43pm UTC](https://discuss.elastic.co/t/netflow-logstash-v9-not-working-not-getting-any-logs/91228/9 "2017-06-29T15:43:29Z")

</div>

Ok I can replay your pcap to my Logstash instance.  
One sample of what I get:

```auto
{
       "netflow" => {
          "destinationIPv4Address" => "10.99.252.50",
                 "octetTotalCount" => 65,
        "destinationTransportPort" => 53,
              "flowStartSysUpTime" => 2395375053,
               "sourceIPv4Address" => "10.99.130.239",
                "flowEndSysUpTime" => 2395395322,
        "flowDurationMilliseconds" => 20269,
                "ingressInterface" => 48660,
                         "version" => 10,
                "packetDeltaCount" => 0,
                   "firewallEvent" => 2,
              "protocolIdentifier" => 17,
                "sourceMacAddress" => "00:00:00:00:00:00",
                 "egressInterface" => 26092,
                 "octetDeltaCount" => 0,
             "sourceTransportPort" => 65105,
                "packetTotalCount" => 1
    },
    "@timestamp" => 2017-06-29T13:58:28.000Z,
      "@version" => "1",
          "host" => "172.16.32.201",
          "tags" => []
}

```

I'm not sure what the issue is. These docker containers are given an IP on a private network on the host side right? So the Barracuda firewall cannot reach the container unless there is some port forwarding setup on the host?

---

<div class="post-metadata">

**Author:** ![jorritfolmer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jorritfolmer/32/20327_2.png) [@jorritfolmer](https://discuss.elastic.co/u/jorritfolmer)\
**Post date:** [June 29, 2017, 4:04pm UTC](https://discuss.elastic.co/t/netflow-logstash-v9-not-working-not-getting-any-logs/91228/10 "2017-06-29T16:04:11Z")

</div>

Thanks for the pcap:

> <https://github.com/logstash-plugins/logstash-codec-netflow/commit/aab1f168d792ee31d163c11cbe93fd5acb74ce74>

---

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [June 30, 2017, 7:20pm UTC](https://discuss.elastic.co/t/netflow-logstash-v9-not-working-not-getting-any-logs/91228/11 "2017-06-30T19:20:58Z")

</div>

yes i actually start the container with the following run command.:

"docker container run -v /srv/logstash/config-dir:/config-dir -v /graylog/data/logstash:/usr/share/logstash/data --link graylog:graylog -p 1535:1535/udp --name logstash pkahr/docker-logstash-gelf -f /config-dir/logstash.conf"

it seems like it's more of an issue with docker. But when i start the container with -it and start a tcpdump inside the container on port 1535, i successfully get inputs. I don't know how to debug it further. I even build my own docker with "netflow and gelf" plugin, didn't change a thing, everything is still dropped by logstash. I have no output on stdout, or on the gelf that is linked to graylog.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2017, 7:20pm UTC](https://discuss.elastic.co/t/netflow-logstash-v9-not-working-not-getting-any-logs/91228/12 "2017-07-28T19:20:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
