elastiflow / elastiflow_for_elasticsearch

A solution for using the ElastiFlow Unified Collector with the Elastic Stack (Elasticsearch and Kibana).
Other
21 stars 7 forks source link

input type distinguish #1

Closed luweijun1992 closed 3 years ago

luweijun1992 commented 3 years ago

image: elastiflow/flow-collector:v5.0.0-beta.1.2 elastic: 7.10.1 Only one 9995/udp is seen in the environment variable. How to distinguish between NetFlow, sFlow and ipfix. The port is not distinguished. When the traffic flows to "elastiflow unified flow collector", different protocols will be distinguished automatically.

robcowart commented 3 years ago

Yes. The collector automatically figures out the type of flow record and handles it accordingly.