# SRC & DST\_port visualizations (NETFlow)

**URL:** <https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033>\
**Category:** Kibana\
**Created:** [May 26, 2016, 8:57am UTC](https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033 "2016-05-26T08:57:32Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![brayndasilva](https://avatars.discourse-cdn.com/v4/letter/b/2bfe46/32.png) [@brayndasilva](https://discuss.elastic.co/u/brayndasilva)\
**Post date:** [May 26, 2016, 8:57am UTC](https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033/1 "2016-05-26T08:57:32Z")

</div>

Hi,

I'm working with NETFlow data and am making a few visualizations and was hoping to have some questions answered by someone who has more experience with it.

This is what I have right now  
[![](http://i.imgur.com/o1RvoE4.png) ](http://i.imgur.com/o1RvoE4.png)

If you were to open the legend the info would be there including the specific port numbers, but I would prefer to name the port numbers. e.g instead of showing 443 it would show HTTPS in the legend and tooltip.

Is this possible?

---

<div class="post-metadata">

**Author:** ![brayndasilva](https://avatars.discourse-cdn.com/v4/letter/b/2bfe46/32.png) [@brayndasilva](https://discuss.elastic.co/u/brayndasilva)\
**Post date:** [May 26, 2016, 11:59am UTC](https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033/2 "2016-05-26T11:59:29Z")

</div>

I believe this is not possible on Kibana level, but it should be possible somehow.

I tried to use the following plugin, but it didn't quite work. [https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html)

```
filter {
  mutate {
    replace => { "443" => "%{netflow.l4_src_port}: HTTPS" }
  }
}
```

Anything else I can try to change the value in a field before it reaches kibana?

---

<div class="post-metadata">

**Author:** ![fetchmelogs](https://avatars.discourse-cdn.com/v4/letter/f/c2a13f/32.png) [@fetchmelogs](https://discuss.elastic.co/u/fetchmelogs)\
**Post date:** [May 26, 2016, 12:17pm UTC](https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033/3 "2016-05-26T12:17:18Z")

</div>

I'm not a pro , but I believe this cannot be solved in Kibana.

If you use logstash, consider the use of the translate filter.

It will allow you to specify a dictionary like:

"443" : "HTTPS"  
"80" : "HTTP"

..which I believe can solve your issue.

Link:  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html)

---

<div class="post-metadata">

**Author:** ![brayndasilva](https://avatars.discourse-cdn.com/v4/letter/b/2bfe46/32.png) [@brayndasilva](https://discuss.elastic.co/u/brayndasilva)\
**Post date:** [May 26, 2016, 12:30pm UTC](https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033/4 "2016-05-26T12:30:11Z")

</div>

Installed the plugin with`/opt/logstash$ bin/plugin install logstash-filter-translate`

Configuration of the filter looks like this right now

```
filter {
  translate {
    dictionary => [ "80", "HTTP",
                    "443", "HTTPS" ]
  }
}
```

Trying it out atm

---

<div class="post-metadata">

**Author:** ![brayndasilva](https://avatars.discourse-cdn.com/v4/letter/b/2bfe46/32.png) [@brayndasilva](https://discuss.elastic.co/u/brayndasilva)\
**Post date:** [May 26, 2016, 12:56pm UTC](https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033/5 "2016-05-26T12:56:52Z")

</div>

Updated my config to the following

```
filter {
  translate {
    field => "netflow.l4_src_port"
    dictionary => [ "80", "HTTP",
                    "443", "HTTPS",
                    "161", "SNMP" ]
  }
}
```

I tested the config and it came out OK and restarted the service. After a few minutes of running I checked the field of the new records and it's still just the number. Am I missing something?

[![](http://i.imgur.com/qOuzZtT.png) ](http://i.imgur.com/qOuzZtT.png)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 26, 2016, 10:08pm UTC](https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033/6 "2016-05-26T22:08:06Z")

</div>

It's probably [https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-override](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-override)

---

<div class="post-metadata">

**Author:** ![brayndasilva](https://avatars.discourse-cdn.com/v4/letter/b/2bfe46/32.png) [@brayndasilva](https://discuss.elastic.co/u/brayndasilva)\
**Post date:** [May 27, 2016, 7:13am UTC](https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033/7 "2016-05-27T07:13:15Z")

</div>

Tried it out and my configuration looks like the following at the moment, but it won't do it.

Could it be because the data is numeric and I'm trying to "translate" it into text? Something with datatypes conflicting perhaps

```
filter {
translate {
field => "netflow.l4_src_port"
override => "true"
dictionary => [ "80", "HTTP",
"443", "HTTPS",
"161", "SNMP" ]
}
}
```
this can be moved to Logstash if possible
```
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 29, 2016, 10:36am UTC](https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033/8 "2016-05-29T10:36:36Z")

</div>

> Could it be because the data is numeric and I'm trying to "translate" it into text? Something with datatypes conflicting perhaps

Yes, that's most likely the problem. If the field has been mapped as an integer you can't store documents with that field being a string.

---

<div class="post-metadata">

**Author:** ![brayndasilva](https://avatars.discourse-cdn.com/v4/letter/b/2bfe46/32.png) [@brayndasilva](https://discuss.elastic.co/u/brayndasilva)\
**Post date:** [May 30, 2016, 11:15am UTC](https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033/9 "2016-05-30T11:15:06Z")

</div>

Alright, that makes sense.

This is what my mapping for the specific fields look like

```
"l4_dst_port" : {
"type" : "long"
},
"l4_src_port" : {
"type" : "long"
},
```

How can I change the type to "string"? I use indexes that are created daily, anything I need to keep in mind with that?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 30, 2016, 7:40pm UTC](https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033/10 "2016-05-30T19:40:55Z")

</div>

Just change your index template and wait for the next day.

---

<div class="post-metadata">

**Author:** ![brayndasilva](https://avatars.discourse-cdn.com/v4/letter/b/2bfe46/32.png) [@brayndasilva](https://discuss.elastic.co/u/brayndasilva)\
**Post date:** [May 31, 2016, 12:08pm UTC](https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033/11 "2016-05-31T12:08:08Z")

</div>

Would appreciate some help with changing my index template if possible.

This is what my default template looks like  
[http://pastebin.com/aCkyHySC](http://pastebin.com/aCkyHySC)

Don't seem to find the field I'm looking for, should I manually add it?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 31, 2016, 4:46pm UTC](https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033/12 "2016-05-31T16:46:20Z")

</div>

Yes, you need to add your field. Add it alongside `@version`, for example.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:51pm UTC](https://discuss.elastic.co/t/src-dst-port-visualizations-netflow/51033/13 "2017-07-06T13:51:57Z")

</div>


