Packetbeat supports capturing all messages sent or received by the server on which Packetbeat is installed:
packetbeat.interfaces.device: any
But when I set the output to Elasticsearch, I found that the field interface.device does not exist on its log . In other words, How to distinguish netflow from different interface device in log?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.