robcowart / elastiflow

Network flow analytics (Netflow, sFlow and IPFIX) with the Elastic Stack
Other
2.49k stars 598 forks source link

no data in threats #721

Closed hans-mayer closed 3 years ago

hans-mayer commented 3 years ago

Dear Support Team, dear All,

I am running elk stack 7.15.1 on Debian. I downloaded and installed flow-collector_5.1.10_linux_amd64.deb and kibana-7.12.x-codex-dark.ndjson A mikrotik router is sending netflow V5 datagrams. I see in almost all elastiflow menu nice diagrams and graphs, nicer than the build in filebeat netflow coming with the elk stack. But there is the "threats" menu which has no data and stays empty. OK, I could remove this not working menu from the dashboard. But I am running elastiflow 3.4.1 since years on a different server. There the "threats" menu is working and it would be nice to have it in the new version too. Any ideas where I have to turn the screws that I see data also in this menu.

Kind regards Hans

--

robcowart commented 3 years ago

As mentioned in the readme of this now deprecated repository, please use the ElastiFlow Community Slack for help related to the new ElastiFlow.

For the Threats dashboard to be populated, you must enable the integration with RiskIQ PassiveTotal.

hans-mayer commented 3 years ago

Hi Rob,

many thanks fir your hint.

// Hans