robcowart / elastiflow

Network flow analytics (Netflow, sFlow and IPFIX) with the Elastic Stack
Other
2.48k stars 592 forks source link

Wrong event time #302

Closed MagistrYoda closed 5 years ago

MagistrYoda commented 5 years ago

Started to use this amazing project recently. Now i'am getting weird issue with event times. To filter thing out and show i did several dns request. I do have timezone GMT+5

So. 3 times this изображение time of requests is 26/Apr/2019 20:20:32

Corresponded logs is kibana изображение

19:28:24

Netflow_use_lastswitch is off use dockerized setup Several devices: dlinks with sflow and mikrotik with netflow/9 2 core cpu / 16gb. There is not much flows, cpu almost half loaded

Would you kindly provide some explanation? I did build docker (with docker_build.sh). Changed mikrotik to netflow/5 an ipfix and nothing changed

MagistrYoda commented 5 years ago

Turn out that router got wrong ntp source and time skewed a bit (actually lot bigger than a bit, lol).