# ntopng-ELK setup

**URL:** <https://discuss.elastic.co/t/ntopng-elk-setup/160549>\
**Category:** Kibana\
**Created:** [December 12, 2018, 1:21pm UTC](https://discuss.elastic.co/t/ntopng-elk-setup/160549 "2018-12-12T13:21:13Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![swathikothapu](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@swathikothapu](https://discuss.elastic.co/u/swathikothapu)\
**Post date:** [December 12, 2018, 1:21pm UTC](https://discuss.elastic.co/t/ntopng-elk-setup/160549/1 "2018-12-12T13:21:13Z")

</div>

Hello,

Could you please help us on this,

how to see ntopng data in Kibana dashboard, and how to setup ELK in linux

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [December 12, 2018, 9:20pm UTC](https://discuss.elastic.co/t/ntopng-elk-setup/160549/2 "2018-12-12T21:20:35Z")

</div>

Hi  
Can you please explain more what do u mean by ntopng ELK set up ?

For just the basic stack set up you could refer to our documentation link here which explains everything [https://www.elastic.co/guide/en/elastic-stack/current/installing-elastic-stack.html](https://www.elastic.co/guide/en/elastic-stack/current/installing-elastic-stack.html).

Cheers  
Rashmi

---

<div class="post-metadata">

**Author:** ![swathikothapu](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@swathikothapu](https://discuss.elastic.co/u/swathikothapu)\
**Post date:** [December 13, 2018, 4:47am UTC](https://discuss.elastic.co/t/ntopng-elk-setup/160549/3 "2018-12-13T04:47:45Z")

</div>

Thank you for reply,

I want to show ntopng flow on kibana dash board.

ntopng - elasticsearch - kibana

\*\*\*) Is it possible to do

Thanks  
swathi

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 13, 2018, 6:27am UTC](https://discuss.elastic.co/t/ntopng-elk-setup/160549/4 "2018-12-13T06:27:05Z")

</div>

It seems like ntopng supports Elasticsearch, so I guess it should be possible:

> **[Exploring your traffic using ntopng with ElasticSearch+Kibana](https://www.ntop.org/ntopng/exploring-your-traffic-using-ntopng-with-elasticsearchkibana/)**
>
> ntopng allows you to export monitoring data do external sources. For low-traffic sites, SQLite and the ntopng historical interface can be a good option. As your traffic increases you are forced to …

> **[ntopng goes Elastic: Introducing ElasticSearch 6 Support](https://www.ntop.org/ntopng/ntopng-goes-elastic-introducing-elasticsearch-6-support/)**
>
> As you ntopng users know, out of the Elastic toolset ntopng supports both ElasticSearch and LogStash. You can use them using the -F flag: –dump-flows|-F\] | Dump expired flows. Mo…

I have however never used it, so if you are looking for help setting it up I am afraid I will not be able to help.

---

<div class="post-metadata">

**Author:** ![swathikothapu](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@swathikothapu](https://discuss.elastic.co/u/swathikothapu)\
**Post date:** [December 13, 2018, 10:48am UTC](https://discuss.elastic.co/t/ntopng-elk-setup/160549/5 "2018-12-13T10:48:17Z")

</div>

did anyone tried this.

Ntopng - elasticseach - kibana

Thanks  
swathi

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [December 13, 2018, 11:28am UTC](https://discuss.elastic.co/t/ntopng-elk-setup/160549/6 "2018-12-13T11:28:12Z")

</div>

Haven't tried it, but I have been looking at it once in a while.

I am no expert with ntop, but I think that ntopng is just a frontend to visualize the flow data. So you cannot export anything from ntopng into Elasticsearch. What you want, is to export the flow data into Elasticsearch and then present it in Kibana.  
So you probably need nProbe. It is a commercial product by ntop and they also sell an Elasticsearch exporter for it. So that's probably the easiest way.  
Logstash Netflow codec also seems to support nProbe's flow as in input, so that would be another way.

With a little searching around the web you'll find enough information how to proceed.  
If not, you can always contact ntop support and ask for help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2019, 11:28am UTC](https://discuss.elastic.co/t/ntopng-elk-setup/160549/7 "2019-01-10T11:28:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
