# \[Solved\] Output kafka netflow codec

**URL:** <https://discuss.elastic.co/t/solved-output-kafka-netflow-codec/83005>\
**Category:** Logstash\
**Created:** [April 20, 2017, 8:07am UTC](https://discuss.elastic.co/t/solved-output-kafka-netflow-codec/83005 "2017-04-20T08:07:22Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![sangrho](https://avatars.discourse-cdn.com/v4/letter/s/ac8455/32.png) [@sangrho](https://discuss.elastic.co/u/sangrho)\
**Post date:** [April 20, 2017, 8:07am UTC](https://discuss.elastic.co/t/solved-output-kafka-netflow-codec/83005/1 "2017-04-20T08:07:22Z")

</div>

Hello.  
I have been tried integrate logstash and kafka with netflow data.

Before this try, I did integrate logstash, nifi and kafka like below,

```
input{
  file{
    path =>"*.pcap"
    codec => netflow { versions => [5]}
   }
}
output{
  Send NiFi with UDP or TCP
}

```

It is works, but integration without nifi is not working like below,

```
input{
  file{
    path =>"*.pcap"
   }
}
output{
  kafka {
   codec => netflow{ version => [5]}
   topic_id => "topic"
  }
}

```

If ' **codec{}**' of netflow is located in 'input{file{', "%{timestamp}, %{host}, %{message}" is printed in kafka consumer. And If ' **codec{}**' is not located in anywhere, the binary value of netflow can be printed in kafka consumer.

So how can the netflow decoded is printed in kafka consumer?

logstash version : 5.3  
kafka version : 0.10

> Solved

input{  
file{  
path =\>"\*.pcap"  
codec =\> netflow { versions =\> [5]}  
}  
}  
output{  
kafka{  
**codec =\> json**  
topic\_id =\> "test"  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2017, 8:07am UTC](https://discuss.elastic.co/t/solved-output-kafka-netflow-codec/83005/2 "2017-05-18T08:07:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
