my configuration :
input {
udp {
port => 9556
codec => netflow {
versions => [5]
}
type => "Netflow"
}
}
output {
if ( [type] == "Netflow" ) {
elasticsearch {
hosts => ["localhost:9200"]
index => "netflow-%{+YYYY.MM.dd}"
}
}
}
netstat -au :
udp6 0 0 [::]:9556 [::]:*
i see UDP6 but my flow is for ipv4
With TCPDUMP i see my netflow flow
i don't understand , why i have a index in kibana but 0 DATA