Comments (3)
You will notice that there is an es-6.0.0-pre branch. I will be completing a new release for 6.0.0 now that it is GA. In the meantime the index template from the es-6.0.0-pre branch should work.
from elastiflow.
hi -thanks for developing this tool - looks amazing.
i tried your es-6.0.0-pre branch ( had other issues trying to get 5.x working ) and attempted to push some captures into logstash..
i'm not sure i'm pushing the captures in correctly, is
cat my.pcap | nc -4 -u 10.1.1.1 2055
enough?
none get indexed - i just get ( i think i got same result with live data ):
[2017-12-02T13:24:43,194][WARN ][logstash.codecs.netflow ] Ignoring Netflow version v0
[2017-12-02T13:24:43,194][WARN ][logstash.codecs.netflow ] Ignoring Netflow version v54467
[2017-12-02T13:24:43,195][WARN ][logstash.codecs.netflow ] Ignoring Netflow version v1780
[2017-12-02T13:24:43,196][WARN ][logstash.codecs.netflow ] Ignoring Netflow version v36618
[2017-12-02T13:24:43,196][WARN ][logstash.codecs.netflow ] Ignoring Netflow version v28416
[2017-12-02T13:24:43,197][WARN ][logstash.codecs.netflow ] Ignoring Netflow version v34054
[2017-12-02T13:24:43,197][WARN ][logstash.codecs.netflow ] Ignoring Netflow version v1860
[2017-12-02T13:24:43,197][WARN ][logstash.codecs.netflow ] Ignoring Netflow version v42071
[2017-12-02T13:24:43,198][WARN ][logstash.codecs.netflow ] Ignoring Netflow version v36618
every now and then:
[2017-12-02T13:24:43,343][WARN ][logstash.codecs.netflow ] Invalid netflow packet received (value '56330' not as expected for obj.flow_records)
[2017-12-02T13:24:43,632][WARN ][logstash.codecs.netflow ] Can't (yet) decode flowset id 257 from source id 1, because no template to decode it with has been received. This message will usually go away after 1 minute.
obviously no indexes are created...
any help appreciated...
from elastiflow.
Modified index template for compatibility with Elasticsearch versions 5.4.x
thru 6.1.x
. 638f958
from elastiflow.
Related Issues (20)
- Import PCAP file from a USB File to ElasticFlow HOT 1
- RISKIQ behind proxy HOT 1
- Can't access ElastiFlow 5.0.0 in Docker HOT 2
- Centos 7 Install Logstsh sFlow codec fails HOT 1
- ElasticFlow : Netflow VLAN data is not populated in elastiflow HOT 2
- Elastiflow : Not generating enough data in Elastic HOT 2
- ElasticSearch 7.12 ... just checking :) HOT 3
- I can't see data (elastiflow) in kibana HOT 1
- docker image - flowcoll should recover once elasticsearch become available HOT 3
- index-pattern remain elastiflow empty HOT 8
- Invalid request payload JSON format HOT 4
- Elastic upgrade from 7.10 to 7.12 HOT 5
- source.as.organization.name always public HOT 2
- logstash is running but not able to see Sflow data HOT 3
- netflowv5 mikrotik no data in dashboard HOT 6
- kibana terms list might be incomplete because the request is taking to long HOT 1
- Mapper_parsing_exception HOT 2
- No matching indices found: No indices match pattern "elastiflow-flow-codex-*" HOT 2
- no data in threats HOT 2
- The legacy ElastiFlow is deprecated. TRY THE NEW ELASTIFLOW!!!
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from elastiflow.