T
T
Tibor1282021-05-29 15:34:23
NetFlow
Tibor128, 2021-05-29 15:34:23

Traffic analysis (NetFlow) in ELK?

Colleagues, good afternoon!
Netflow caught fire to export to Elasticsearch, for further analysis. Painfully, everything is beautiful in the screenshots, and the elastic is convenient, really. But in practice I encountered one most unpleasant thing ...
As a collector, I launched Filebeat. Either I don't know how to google, or the alternative is hiding somewhere.
And when setting up the visualization, I run iperf to see if the graph is adequate and I see something completely different from what I expected. Having looked through Discover in kibana, I understand that in elastic records are not about packets, but accumulated data about sessions. Thus, it turns out that there is a high probability that the traffic information will be displayed incorrectly. For example, if I select a time range from 0:00 to 23:59, and someone started downloading a large file at 18:00 and finished the next day, blocking the channel, I won't see it in the report.

So here's the request. Is it possible to force filebeat to send each package to elastic as a separate dock, and if not, what are the alternatives?

Answer the question

In order to leave comments, you need to log in

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question