ipfix template // howto decode interface?
Posted: Wed Sep 22, 2021 2:35 pm
Hi all,
I set up some monitoring on elasticsearch for my traffic flow as ipfix an v9 netflows.
Works fine so far but though I did check to transfer the interfaces I cannot find them in the messages. I'd guess I'd need to write an own schema for the decoding? but at what code are the interfaces? or is it at "standard" codes but different format?
the marks "in interface" & "out interface" are ticked in the selection.
Wireshard does see outputint & inputin when set to cflow, thus looks bit like finding the correct mapping?!
actually when writing the output as debug out with logstash there's no value looking like interface
Best Daniel
I set up some monitoring on elasticsearch for my traffic flow as ipfix an v9 netflows.
Works fine so far but though I did check to transfer the interfaces I cannot find them in the messages. I'd guess I'd need to write an own schema for the decoding? but at what code are the interfaces? or is it at "standard" codes but different format?
the marks "in interface" & "out interface" are ticked in the selection.
Wireshard does see outputint & inputin when set to cflow, thus looks bit like finding the correct mapping?!
actually when writing the output as debug out with logstash there's no value looking like interface
Best Daniel