I've start NetFlow by using this command
/usr/share/logstash/bin/logstash --modules netflow -M netflow.var.input.udp.port=9966 and it works.
But when I look at overview traffic dashboard I see that some host send huge amount of traffic.
And it's only one packet! We have tons of gigabytes per day for this host.
But in fact this host doesn't send this amount of traffic. Maybe field "netflow.bytes" for this host contains strange invalid value.
Can I configure some filters to discard packets with this strange value?