# Vizualize Netflow data in Kibana (used network trafic)

**URL:** <https://discuss.elastic.co/t/vizualize-netflow-data-in-kibana-used-network-trafic/287645>\
**Category:** Kibana\
**Created:** [October 26, 2021, 6:50am UTC](https://discuss.elastic.co/t/vizualize-netflow-data-in-kibana-used-network-trafic/287645 "2021-10-26T06:50:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gmbynkrkrqz](https://avatars.discourse-cdn.com/v4/letter/g/22d042/32.png) [@gmbynkrkrqz](https://discuss.elastic.co/u/gmbynkrkrqz)\
**Post date:** [October 26, 2021, 6:50am UTC](https://discuss.elastic.co/t/vizualize-netflow-data-in-kibana-used-network-trafic/287645/1 "2021-10-26T06:50:07Z")

</div>

Hi,

I would like to create a dashboard on Kibana using the OPNsense Netflow logs to vizualize the bandwith used per source IP.

Here is my logstash config.

```auto
input {
  # OPNsense netflow logs input
  udp {
    port => 10522
    codec => netflow
    tags => ["opnsense_netflow_logs"]
  }
}

filter {

}

output {
  if "opnsense_netflow_logs" in [tags] {
    elasticsearch {
      hosts => "http://localhost:9200"
      index => "opnsense-netflow-%{+YYYY.MM}"
    }
  }
}

```

I receive data in Elasticsearch, but I don't know how to use it to create a graph.

 ![netflow_data_elk](https://us1.discourse-cdn.com/elastic/original/3X/7/c/7ccfe58481f4855326c9e2fc94dc5119941cc2b1.png)

For my tests I started a "wget --limit-rate=200k xxx". My IP is 172.16.10.106.  
Here is the vizualization I created. As you can see, the graph is wrong and I can't even see the download I'm doing.

 ![vizu_1](https://us1.discourse-cdn.com/elastic/original/3X/7/c/7cb3a3c4bf5c2188c77385d43401854ac044b120.png)

 ![vizu_2](https://us1.discourse-cdn.com/elastic/original/3X/c/1/c164677f12b72e642ab33a7da466cd8ad5734abf.png)

Where does the problem come from ?  
Is the Netflow data correct ? If yes, how should I create my vizualization in Kibana ?

Thanks a lot in advance.

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [October 27, 2021, 4:18pm UTC](https://discuss.elastic.co/t/vizualize-netflow-data-in-kibana-used-network-trafic/287645/2 "2021-10-27T16:18:21Z")

</div>

Is it possible that the value for `netflow.ipv4_src_addr.keyword` in your first image is not one of the top values showing in your graph?

I'm also curious as to why you're using moving average instead of something like `sum`.

---

<div class="post-metadata">

**Author:** ![techie.antonio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/techie.antonio/32/77423_2.png) [@techie.antonio](https://discuss.elastic.co/u/techie.antonio)\
**Post date:** [October 28, 2021, 9:30am UTC](https://discuss.elastic.co/t/vizualize-netflow-data-in-kibana-used-network-trafic/287645/3 "2021-10-28T09:30:49Z")

</div>

You should be using TSVB as it will allow you to use pipeline aggregations and formulas, which are all necessary to achieve what you want.

Alternatively, just use ElastiFlow where all of this stuff has already been done for you. We use this where I work, and I use it for a home lab. The Basic License is free and should cover all of the data fields exported by OPNsense. The original ElastiFlow used Logstash, but the new version is a custom developed collector. It is much faster than Logstash or Filebeat, but it also has more netflow-specific features.

> **[Introduction | ElastiFlow](https://docs.elastiflow.com/docs/)**
>
> ElastiFlow™ Unified Flow Collector

This is how ElastiFlow uses TSVB to turn the bytes value into a bandwdith value.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/5/7527ac4e67e7686809224b74d5be5fa4a59a8416.png)

To display the value properly in bits/s, you would also add

![image](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1c620149db0698978bec20ccd190ba3bc3f14637.png)

When it comes to using Elastic for network data, the ElastiFlow team is the only people I have talked to which seem to know what they are talking about. They know the data, the use-cases and they know Elastic, maybe better than Elastic, definitely better than the solution architect we talked to.

---

<div class="post-metadata">

**Author:** ![gmbynkrkrqz](https://avatars.discourse-cdn.com/v4/letter/g/22d042/32.png) [@gmbynkrkrqz](https://discuss.elastic.co/u/gmbynkrkrqz)\
**Post date:** [November 5, 2021, 8:03am UTC](https://discuss.elastic.co/t/vizualize-netflow-data-in-kibana-used-network-trafic/287645/4 "2021-11-05T08:03:18Z")

</div>

Thanks a lot for your answer.

I spent a lot of time trying the same settings as you, but it's still not working... (I want the values to be in bytes, that's why the settings are not exactly the same).

We would like to avoid setting up another product like ElastiFlow.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/b/7b1f3e87d69f1b96d2c56abcbf8c015dfdf01805.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/4/94379602bdda98a43fa35ba40198c04d4379ccf2.png)

I think I'm gonna give up.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2021, 8:03am UTC](https://discuss.elastic.co/t/vizualize-netflow-data-in-kibana-used-network-trafic/287645/5 "2021-12-03T08:03:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
