I'm very new to ELK... So, I've got the following:
Elasticsearch v6.0.0 + X-Pack
Logstash v6.0.0 + X-Pack
Kibana v6.0.0 + X-Pack
I want to collect netflow data. The issue is:
/usr/share/logastash/bin/logstash --modules netflow --setup
and got installed template, dashboards and etc. in Kibana. OK.
Then I've start to send netflow data from my ASA, after 10 minutes messages about missing "template to decode" gone and I've got data in Kibana. BUT!
There are two fields in template - netflow.bytes and netflow.packets - and there are no such data in Discover app in Kibana. What should I do with this? Almost all graphs and charts referrs to this fields. Am I missing something?
Please help to solve this problem!