Let this run just long enough for netflow data to come in then revert the changes to disable it. This should create a /var/log/logstash/logstash.log file with some more details. Please PM me a copy of this file as well as a profile from Admin > System > System Status > Download System Profile.
cdienger wrote:Please provide a screenshot of the events as seen in the dashboard. Make sure the events are expanded so that we can see all the fields of the event.
When we checked the server the next day after applying the input filters, NLS stopped working and upon checking the unique hosts went from 30 to 1010.
For now I disabled netflow config on input, filter and output. But after reboot some tabs became unable to access, specially Admin - cluster
You can check out the attachments for the screenshots and also the system profile. I don't know what happened to the server anymore, did I do something wrong?
Support Edit: system-profile (2).tar.gz downloaded and shared with team
You do not have the required permissions to view the files attached to this post.
We can enable it after increasing the memory, however, there is still no explanation why we had 1010 sources.
Also, do we have an update on the review of the system profile? It may happen again and Nagios might crash after enabling NetFlow.
Looking at your profile, it's pretty likely that there's a field in the netflow data that's overriding the normal host field. Let's change your filter once more.