# Newbie qn: ingesting netflow

**URL:** <https://discuss.elastic.co/t/newbie-qn-ingesting-netflow/283000>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 1, 2021, 7:19am UTC](https://discuss.elastic.co/t/newbie-qn-ingesting-netflow/283000 "2021-09-01T07:19:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hjazz6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hjazz6/32/79007_2.png) [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Post date:** [September 1, 2021, 7:19am UTC](https://discuss.elastic.co/t/newbie-qn-ingesting-netflow/283000/1 "2021-09-01T07:19:29Z")

</div>

Hi all,

I'm a newbie in ELK, and would like to send Netflow data to ElasticSearch via Filebeat (both on the same server). I'm starting to read all the documentation and configuration guides, but I'm a bit confused about the Filebeat configuration.

It seems like there are 2 ways to configure Netflow input: manually using `filebeat.inputs` in `filebeat.yml`, or using the Netflow module. Am I right to say if I choose to use the filebeat module, I don't have to modify the `filebeat.yml` file other than the ES and Kibana portion (setting the `host` to `0.0.0.0`)? I'll just need to modify `netflow.yml` (also setting the `host` to `0.0.0.0`) and enable it?

My netflow (ipfix) will also include an `app_id` field that was added by the vendor. Will the netflow module be able to handle it?

Thank you.

---

<div class="post-metadata">

**Author:** ![Marius\_Iversen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_iversen/32/68988_2.png) [@Marius\_Iversen](https://discuss.elastic.co/u/Marius_Iversen)\
**Post date:** [September 1, 2021, 9:38am UTC](https://discuss.elastic.co/t/newbie-qn-ingesting-netflow/283000/2 "2021-09-01T09:38:42Z")

</div>

That's correct @hjazz6 , when using a module, the steps should be quite similar for any module:

1. run `filebeat modules enable MODULENAME`, in this case netflow.
2. Configure the `output.elasticsearch` and the `setup.kibana` parameters in` filebeat.yml`.
3. Configure the relevant module settings in `./modules.d/modulename.yml`
4. Run `filebeat setup`
5. Either start the `filebeat` service, or if you just want to test it, you can run it in the foreground with `filebeat -e`, so you can see the logs directly in your CLI.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 29, 2021, 11:39am UTC](https://discuss.elastic.co/t/newbie-qn-ingesting-netflow/283000/3 "2021-09-29T11:39:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
