Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Netflow sent by Cisco ASA 9.6(1) doesn't contain IN_BYTES and IN_PACKETS #112

Closed
BROngineer opened this issue Dec 7, 2017 · 4 comments · May be fixed by elastic/logstash#10001
Closed

Comments

@BROngineer
Copy link

BROngineer commented Dec 7, 2017

Hello!

Elasticsearch v6.0.0 + X-Pack
Logstash v6.0.0 + X-Pack
Kibana v6.0.0 + X-Pack
OS: Ubuntu 16.04.1 x86-64

The issue is that Cisco ASA 9.6(1) doesn't send IN_PACKETS and IN_BYTES fields - ASA Netflow spec. For bytes count it sends the following fields:
NF_F_FWD_FLOW_DELTA_BYTES - The delta number of bytes from source to destination.
NF_F_REV_FLOW_DELTA_BYTES - The delta number of bytes from destination to source.
and no data for packets count.
Any ideas how to update templates and dashboards?
Pcap is attached.
netflow-12055.zip

@rol-ubiqube
Copy link

Hi, as that information is available in Cisco ASA 9.8 and was doubting 9.6 didn't have it, I just did a quick check in your pcap, and yes it is available.
You can see this in flowset id = 0 (template) for template id 263 - fields 18 (initiatorOctets) and 19 (responderOctets).
And it's only necessary to use the correspondent 231 and 232 of netflow codec.
Regards

@jorritfolmer
Copy link
Contributor

Closing this issue, as @rol-ubiqube pointed out the bytes field in the pcap. Thanks for taking a look btw!

@acheraime
Copy link

Was his issue resolved? I have the same problem running ASA 9.1.

@rol-ubiqube
Copy link

@acheraime either in ASA 9.1 documentation or ideally in pcap, you should check if the required fields are available (as per my previous comment - #112 (comment).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants