There's no "OUT_BYTES" field when I parse netflow through logstash

(張皓翔) #1

As title, when I use logstash to parse netflow and ingest flow data into elasticsearch, I found the data in ES is lack of "OUT_BYTES" field.
this is the data in ES:

  "_index": "netflow-%{year}-%{month}-%{day}",
  "_type": "doc",
  "_id": "QnjmS2EBwY8ORgd4n7yl",
  "_version": 1,
  "_score": null,
  "_source": {
    "netflow": {
      "in_pkts": 13,
      "version": 5,
      "src_tos": 0,
      "engine_type": 1,
      "ipv4_next_hop": "",
      "dst_as": 0,
      "dst_mask": 0,
      "sampling_algorithm": 0,
      "src_mask": 0,
      "flow_records": 24,
      "output_snmp": 0,
      "last_switched": "2018-01-31T10:58:40.971Z",
      "first_switched": "2018-01-31T10:58:40.971Z",
      "ipv4_dst_addr": "",
      "tcp_flags": 0,
      "ipv4_src_addr": "",
      "protocol": 6,
      "src_as": 0,
      "input_snmp": 191,
      "l4_dst_port": 10029,
      "sampling_interval": 0,
      "l4_src_port": 443,
      "in_bytes": 5548,
      "flow_seq_num": 1259678413,
      "engine_id": 2
    "@timestamp": "2018-01-31T10:58:44.972Z",
    "host": "",
    "@version": "1"
  "fields": {
    "netflow.first_switched": [
    "@timestamp": [
    "netflow.last_switched": [
  "sort": [

logstash config:

		host => "120.127.XXX.XX"
		port => 5556
		codec => netflow	
elasticsearch {
                hosts => ["120.127.XXX.XX:9200"]
				index => "netflow-%{year}-%{month}-%{day}"
		stdout{codec=> rubydebug}

thank you in advance :slight_smile:

(Jared Carey) #2

Why not use the netflow module?

I’m not an expert on netflow, but I’d say there is a little extra processing that is done just by looking at the configuration that the module uses (plus you get the kibana dashboards)

(Robert Cowart) #3

You are sending Netflow version 5 flows. Netflow v5 supports ONLY ingress flows, so there is no out_bytes. If you want out_bytes (or an equivalent field) you will need to send Netflow v9 and enable egress flows on the device sending the data.

BTW, a better alternative to the Logstash Netflow module is here...

The Logstash Netflow module was based on v1.0.0 of ElastiFlow and is now quite a bit behind.

(system) #4

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.