# Newbie playing with netflow (with nProbe) + ELK. Everything running and now what

**URL:** <https://discuss.elastic.co/t/newbie-playing-with-netflow-with-nprobe-elk-everything-running-and-now-what/60269>\
**Category:** Kibana\
**Created:** [September 12, 2016, 9:06am UTC](https://discuss.elastic.co/t/newbie-playing-with-netflow-with-nprobe-elk-everything-running-and-now-what/60269 "2016-09-12T09:06:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bartplessers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bartplessers/32/11849_2.png) [@bartplessers](https://discuss.elastic.co/u/bartplessers)\
**Post date:** [September 12, 2016, 9:06am UTC](https://discuss.elastic.co/t/newbie-playing-with-netflow-with-nprobe-elk-everything-running-and-now-what/60269/1 "2016-09-12T09:06:01Z")

</div>

Hello,

Just bought a UBNT router with netflow capabilities.

I setup **netflow** , and configured a windows server with ELK.

[http://www.secureict.info/2015/11/process-netflow-with-nprobe-and.html](http://www.secureict.info/2015/11/process-netflow-with-nprobe-and.html)  
[http://www.secureict.info/2015/11/process-netflow-with-nprobe-and\_13.html](http://www.secureict.info/2015/11/process-netflow-with-nprobe-and_13.html)  
[http://www.secureict.info/2015/11/process-netflow-with-nprobe-and\_91.html](http://www.secureict.info/2015/11/process-netflow-with-nprobe-and_91.html)

Now I see a basic graph on kibana, but I want

- an historical view
- of my IP adresses (maybe with hostnames)
- and their bandwidth usage

to answer my question: "wich of my clients consumes howmuch bandwith on what time" Granularity of period should at least be 1h.

Is this possible?  
Can somebody point me to some good information (not to difficult for a newbie as me... 🙂 )

thanx in advance!  
Bart

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 12, 2016, 9:08am UTC](https://discuss.elastic.co/t/newbie-playing-with-netflow-with-nprobe-elk-everything-running-and-now-what/60269/2 "2016-09-12T09:08:28Z")

</div>

> [@bartplessers](#):
>
> - an historical view

Which will be possible when you have more data.

> [@bartplessers](#):
>
> - of my IP adresses (maybe with hostnames)

That should already show up, hostnames will depend on reverse DNS.

> [@bartplessers](#):
>
> - and their bandwidth usage

That's where you run an aggregation.

Did you run through the second one of those links?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:39pm UTC](https://discuss.elastic.co/t/newbie-playing-with-netflow-with-nprobe-elk-everything-running-and-now-what/60269/3 "2017-07-06T13:39:08Z")

</div>


