as the topic says netflow information (v5 and v9) is sent to logstash. Both are processed and stored in elasticsearch as expected. When opening the index in Kibana only v5 logs are shown although there are much less of this version than of v9, a ration of 1:30. Only after defining a filter which excludes v5 logs v9 logs are shown.
complete stack on version 5.4