# NetFlow v9 Interface/VRF mappings

**URL:** <https://discuss.elastic.co/t/netflow-v9-interface-vrf-mappings/152186>\
**Category:** Logstash\
**Created:** [October 12, 2018, 7:59am UTC](https://discuss.elastic.co/t/netflow-v9-interface-vrf-mappings/152186 "2018-10-12T07:59:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![1fe60245fe160bc0f8ab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/1fe60245fe160bc0f8ab/32/62635_2.png) [@1fe60245fe160bc0f8ab](https://discuss.elastic.co/u/1fe60245fe160bc0f8ab)\
**Post date:** [October 12, 2018, 7:59am UTC](https://discuss.elastic.co/t/netflow-v9-interface-vrf-mappings/152186/1 "2018-10-12T07:59:16Z")

</div>

Hi all,

We're currently using Logstash's NetFlow plugin in order to decode and process all sorts of NetFlow streams (v5, v9, IPFIX) coming from various sources (Checkpoint, Cisco, VMware and others).

We've encountered a problem in NetFlow v9 sent from Cisco routers, where every 5 minutes (or another configurable interval) the router sends a mapping between its interface names and random numbers (standard key-value mapping), and it does the same for VRF names and numbers. In the actual NetFlow packets, we receive a field called "interface\_snmp" or "VRF\_ID" which is a number.

Is there any way to translate those fields? We've thought about running a ruby code when the mapping messages are being received which will edit a dictionary file in all of the Logstash nodes (then later decode interface numbers using a standard dictionary filter). However, this is rather complex (regardless of performance issues) and our engineers have recommended on simply saving the mappings to a different index and then translate via a python script which will update the documents in the NetFlow index. We have used ElastiFlow in the past and could easily reuse this project again if it offers a solution to this problem...

Any thoughts?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2018, 7:59am UTC](https://discuss.elastic.co/t/netflow-v9-interface-vrf-mappings/152186/2 "2018-11-09T07:59:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
