# ElastiFlow Community

**URL:** https://forum.elastiflow.com/c/community/4.md?page=1

[Latest](https://forum.elastiflow.com/latest.md) · [Categories](https://forum.elastiflow.com/categories.md) · [Tags](https://forum.elastiflow.com/tags.md)

**Page:** 2

---

## [New Blog: Using Flow Data to Optimize Firewall Rules: Best Practices and Cloud Migration Insights](https://forum.elastiflow.com/t/new-blog-using-flow-data-to-optimize-firewall-rules-best-practices-and-cloud-migration-insights/317)

<div class="topic-metadata">

**Author:** [@jessica](https://forum.elastiflow.com/u/jessica)\
**Replies:** 0\
**Last updated:** [July 22, 2025, 4:37pm UTC](https://forum.elastiflow.com/t/new-blog-using-flow-data-to-optimize-firewall-rules-best-practices-and-cloud-migration-insights/317 "2025-07-22T16:37:36Z")

</div>

A new blog post that just dropped: “Using Flow Data to Optimize Firewall Rules: Best Practices and Cloud” from Elastiflow. If you’re looking to improve your network security posture, enhance performance, or get a handle…

---

## [SNMP enrichment with non default community string](https://forum.elastiflow.com/t/snmp-enrichment-with-non-default-community-string/313)

<div class="topic-metadata">

**Author:** [@tstevens.cisco.com](https://forum.elastiflow.com/u/tstevens.cisco.com)\
**Replies:** 3\
**Last updated:** [July 18, 2025, 9:24pm UTC](https://forum.elastiflow.com/t/snmp-enrichment-with-non-default-community-string/313 "2025-07-18T21:24:21Z")

</div>

I have NetObserv Flow running in docker, working well but seeing one problem - if I change the community string from the default (“public”), SNMP enrichment for interface names no longer works. I just see the IFindexes a…

---

## [Unable to find device](https://forum.elastiflow.com/t/unable-to-find-device/311)

<div class="topic-metadata">

**Author:** [@banjo](https://forum.elastiflow.com/u/banjo)\
**Replies:** 2\
**Last updated:** [July 16, 2025, 12:19pm UTC](https://forum.elastiflow.com/t/unable-to-find-device/311 "2025-07-16T12:19:14Z")

</div>

Has anyone figure out yet what the root cause of this issue? I can snmpwalk on my cisco device and this is my devices.yml enterprise: ip: 10.1.0.10 port: 161 version: 2c communities: - public device\_groups…

---

## [AS PATH Enrichment](https://forum.elastiflow.com/t/as-path-enrichment/304)

<div class="topic-metadata">

**Author:** [@chrismfz](https://forum.elastiflow.com/u/chrismfz)\
**Replies:** 0\
**Last updated:** [June 30, 2025, 6:40pm UTC](https://forum.elastiflow.com/t/as-path-enrichment/304 "2025-06-30T18:40:38Z")

</div>

Hello everyone, I’m currently using a MikroTik router to export NetFlow data, but as you may know, MikroTik doesn’t include BGP-related fields like AS PATH, AS Source, or AS Destination in the flow records. In the past…

---

## [CIDR syntax error for IP address enrichment](https://forum.elastiflow.com/t/cidr-syntax-error-for-ip-address-enrichment/293)

<div class="topic-metadata">

**Author:** [@robertclark](https://forum.elastiflow.com/u/robertclark)\
**Replies:** 8\
**Last updated:** [June 16, 2025, 1:49pm UTC](https://forum.elastiflow.com/t/cidr-syntax-error-for-ip-address-enrichment/293 "2025-06-16T13:49:05Z")

</div>

Seeing the following error in the flow collector log on versions 7.10.3 and 7.11.0: “ipaddr\_enricher.hostname\_enricher.ip/cider\_to\_values”,“caller”:“cidr2value/cidr2value.go:169”,“msg”:“provided value for 192.168.130.16…

---

## [Threats IP Reputation doesn't work](https://forum.elastiflow.com/t/threats-ip-reputation-doesnt-work/280)

<div class="topic-metadata">

**Author:** [@pupilos](https://forum.elastiflow.com/u/pupilos)\
**Replies:** 4\
**Last updated:** [April 16, 2025, 3:16pm UTC](https://forum.elastiflow.com/t/threats-ip-reputation-doesnt-work/280 "2025-04-16T15:16:01Z")

</div>

Hello all, I use Elastiflow 7.9.0 with ELK stack in my LAB environment, and my Threats IP Reputation doesn’t show any data anymore. Kibana doens’t see any fields sec.threat name and here is my flowcoll.yml input config…

---

## [Elastiflow Throughput (bits/s) is different of real data rate](https://forum.elastiflow.com/t/elastiflow-throughput-bits-s-is-different-of-real-data-rate/271)

<div class="topic-metadata">

**Author:** [@wallacegerheim](https://forum.elastiflow.com/u/wallacegerheim)\
**Replies:** 2\
**Last updated:** [March 28, 2025, 2:01pm UTC](https://forum.elastiflow.com/t/elastiflow-throughput-bits-s-is-different-of-real-data-rate/271 "2025-03-28T14:01:10Z")

</div>

Hello. I recently installed my first NetObserv 7.9 and I am sending flow from only one Cisco router. When I compare the throughput on the dashboard, I notice a difference in relation to the real data rate of my Cisco ro…

---

## [How to get appid.yml](https://forum.elastiflow.com/t/how-to-get-appid-yml/265)

<div class="topic-metadata">

**Author:** [@yaslam](https://forum.elastiflow.com/u/yaslam)\
**Replies:** 2\
**Last updated:** [March 25, 2025, 8:07pm UTC](https://forum.elastiflow.com/t/how-to-get-appid-yml/265 "2025-03-25T20:07:20Z")

</div>

Hi everyone. I am trying to setup application enrichment in ElastiFlow following Applications | ElastiFlow but I recognize that you need a file called /etc/elastiflow/app/ipport.yml which is user defined. I don’t mind m…

---

## [Specify domains in \`/etc/elastiflow/app/ipport.yml\`](https://forum.elastiflow.com/t/specify-domains-in-etc-elastiflow-app-ipport-yml/266)

<div class="topic-metadata">

**Author:** [@yaslam](https://forum.elastiflow.com/u/yaslam)\
**Replies:** 3\
**Last updated:** [March 25, 2025, 5:25pm UTC](https://forum.elastiflow.com/t/specify-domains-in-etc-elastiflow-app-ipport-yml/266 "2025-03-25T17:25:19Z")

</div>

Hi everyone. I am wondering if instead of specifying IPs and Ports in the above file, whether it is possible to specify domains. It would make it easier to add rules for applications. Thanks

---

## [Show what private IP addresses are accessing what](https://forum.elastiflow.com/t/show-what-private-ip-addresses-are-accessing-what/263)

<div class="topic-metadata">

**Author:** [@yaslam](https://forum.elastiflow.com/u/yaslam)\
**Replies:** 4\
**Last updated:** [March 14, 2025, 10:08pm UTC](https://forum.elastiflow.com/t/show-what-private-ip-addresses-are-accessing-what/263 "2025-03-14T22:08:25Z")

</div>

If I use client.domain: 192.168.1.147 in the GeoIP map, there are no results. Is it possible to show private IP addresses and what they are accessing in ElastiFlow? Thanks.

---

## [Incredible work](https://forum.elastiflow.com/t/incredible-work/262)

<div class="topic-metadata">

**Author:** [@yaslam](https://forum.elastiflow.com/u/yaslam)\
**Replies:** 6\
**Last updated:** [March 14, 2025, 8:14pm UTC](https://forum.elastiflow.com/t/incredible-work/262 "2025-03-14T20:14:53Z")

</div>

This is the coolest thing I have ever used.

---

## [Join the ElastiFlow Technical Support Team!](https://forum.elastiflow.com/t/join-the-elastiflow-technical-support-team/257)

<div class="topic-metadata">

**Author:** [@daniel.harada](https://forum.elastiflow.com/u/daniel.harada)\
**Replies:** 1\
**Last updated:** [March 10, 2025, 3:10pm UTC](https://forum.elastiflow.com/t/join-the-elastiflow-technical-support-team/257 "2025-03-10T15:10:33Z")

</div>

Hi Community ! We’re expanding our Technical Support Team and looking for a skilled and customer-focused professional to join us. What We’re Looking For: :white\_check\_mark: Experience with Elasticsearch …

---

## [AWS S3 Bucket Flowcoll.yml Example](https://forum.elastiflow.com/t/aws-s3-bucket-flowcoll-yml-example/250)

<div class="topic-metadata">

**Author:** [@tallguy86](https://forum.elastiflow.com/u/tallguy86)\
**Replies:** 12\
**Last updated:** [February 25, 2025, 7:39pm UTC](https://forum.elastiflow.com/t/aws-s3-bucket-flowcoll-yml-example/250 "2025-02-25T19:39:13Z")

</div>

What is the correct path Flowcoll/GO is looking for when its doing a API call to list buckets? I have the follow in my flowcoll.yml file #AWS\_ACCESS\_KEY\_ID: "" AWS\_REGION: "us-east-2" #AWS\_SECRET\_ACCESS\_KEY: "" #EF\_AWS…

---

## [Flowcoll is downloading 70 till 80 Mbyte each hour](https://forum.elastiflow.com/t/flowcoll-is-downloading-70-till-80-mbyte-each-hour/234)

<div class="topic-metadata">

**Author:** [@Hans](https://forum.elastiflow.com/u/Hans)\
**Replies:** 17\
**Last updated:** [February 10, 2025, 8:19pm UTC](https://forum.elastiflow.com/t/flowcoll-is-downloading-70-till-80-mbyte-each-hour/234 "2025-02-10T20:19:00Z")

</div>

Dear All, I realised that the flowcoll process is downloading each hour between 70 MB and 80 MB of data. This happens in exactly 60 minutes intervals after the flowcoll process is started and needs less than a minute in…

---

## [App enrichment in Elastiflow](https://forum.elastiflow.com/t/app-enrichment-in-elastiflow/244)

<div class="topic-metadata">

**Author:** [@garciajdusa](https://forum.elastiflow.com/u/garciajdusa)\
**Replies:** 7\
**Last updated:** [February 8, 2025, 8:53pm UTC](https://forum.elastiflow.com/t/app-enrichment-in-elastiflow/244 "2025-02-08T20:53:37Z")

</div>

Any pointers on how to enable Application enrichment? As soon as I enabled these options, the flowcoll service failed to load after a restart. What am I missing here? EF\_PROCESSOR\_ENRICH\_APP\_ID\_ENABLE: “true” EF\_PROC…

---

## [Panic: interface conversion: interface {} is \[\]interface {}, not uint64](https://forum.elastiflow.com/t/panic-interface-conversion-interface-is-interface-not-uint64/241)

<div class="topic-metadata">

**Author:** [@vmakris](https://forum.elastiflow.com/u/vmakris)\
**Replies:** 4\
**Last updated:** [February 6, 2025, 4:18pm UTC](https://forum.elastiflow.com/t/panic-interface-conversion-interface-is-interface-not-uint64/241 "2025-02-06T16:18:16Z")

</div>

Hello everyone! My elasticflow collector keeps crashing at random times and cannot find the reason… Neflow v9 send by Huawei NE8000. Any idea how to attack the problem? Thanks in advance! Vangelis {"level":"info"…

---

## [Elastiflow Opensearch Output Retry Mechanism Not Working](https://forum.elastiflow.com/t/elastiflow-opensearch-output-retry-mechanism-not-working/239)

<div class="topic-metadata">

**Author:** [@Dynamic\_007](https://forum.elastiflow.com/u/Dynamic_007)\
**Replies:** 5\
**Last updated:** [February 6, 2025, 1:45pm UTC](https://forum.elastiflow.com/t/elastiflow-opensearch-output-retry-mechanism-not-working/239 "2025-02-06T13:45:18Z")

</div>

Dear Elastiflow Team , I have installed Elastiflow version 7.3.2 and configured my Output as Opensearch cluster having 3 nodes each version 2.15.0 , When my opensearch is down for 2 hours, and when it comes up after th…

---

## [Traffic Exporter](https://forum.elastiflow.com/t/traffic-exporter/237)

<div class="topic-metadata">

**Author:** [@azeem11](https://forum.elastiflow.com/u/azeem11)\
**Replies:** 3\
**Last updated:** [February 4, 2025, 1:17pm UTC](https://forum.elastiflow.com/t/traffic-exporter/237 "2025-02-04T13:17:24Z")

</div>

Hi all, I have configured NetFlow and everything working smoothly so far. However, I want to see Ingress and Egress on my devices. I have a router where the connection is 70Mbps. But in the dashboard, it shows me traffi…

---

## [Brand new to Elastiflow. Need help seeing flows in my Dashboards](https://forum.elastiflow.com/t/brand-new-to-elastiflow-need-help-seeing-flows-in-my-dashboards/231)

<div class="topic-metadata">

**Author:** [@garciajdusa](https://forum.elastiflow.com/u/garciajdusa)\
**Replies:** 3\
**Last updated:** [January 29, 2025, 3:29am UTC](https://forum.elastiflow.com/t/brand-new-to-elastiflow-need-help-seeing-flows-in-my-dashboards/231 "2025-01-29T03:29:10Z")

</div>

Just got introduced to Elastiflow a few days ago. Setup Elastic/Kibana, imported the Elastiflow Dashboards. Not seeing any data. I’m sure I hosed the flowcoll.yml file. Just using Community Edition for now. Doublec…

---

## [UPDATE: Fortigate vendor detected application data garbled characters](https://forum.elastiflow.com/t/update-fortigate-vendor-detected-application-data-garbled-characters/229)

<div class="topic-metadata">

**Author:** [@Surge](https://forum.elastiflow.com/u/Surge)\
**Replies:** 1\
**Last updated:** [January 23, 2025, 12:16pm UTC](https://forum.elastiflow.com/t/update-fortigate-vendor-detected-application-data-garbled-characters/229 "2025-01-23T12:16:00Z")

</div>

Since the original post is now locked, I thought I’d provide an update in case anyone stumbles across the original thread. Fortinet confirmed that the garbled data in the vendor application fields is a bug and the fix s…

---

## [Error creating index, an index exists with the same name as the alias](https://forum.elastiflow.com/t/error-creating-index-an-index-exists-with-the-same-name-as-the-alias/223)

<div class="topic-metadata">

**Author:** [@fred](https://forum.elastiflow.com/u/fred)\
**Replies:** 6\
**Last updated:** [January 23, 2025, 9:31am UTC](https://forum.elastiflow.com/t/error-creating-index-an-index-exists-with-the-same-name-as-the-alias/223 "2025-01-23T09:31:51Z")

</div>

Hi all, I am using two Elastiflow instances with Docker, sharing the same configuration, and a Virtual IP (VIP) that migrates between the two instances. When the VIP migrates, I encounter an error: “An index exists wit…

---

## [Flow-collector output to opensearch, what is the specific role for openseach user?](https://forum.elastiflow.com/t/flow-collector-output-to-opensearch-what-is-the-specific-role-for-openseach-user/218)

<div class="topic-metadata">

**Author:** [@fred](https://forum.elastiflow.com/u/fred)\
**Replies:** 2\
**Last updated:** [January 14, 2025, 1:39pm UTC](https://forum.elastiflow.com/t/flow-collector-output-to-opensearch-what-is-the-specific-role-for-openseach-user/218 "2025-01-14T13:39:43Z")

</div>

Hi all, I’m using a flow collector to capture NetFlow data and send it to OpenSearch. I’ve created a specific user in OpenSearch and assigned cluster-level permissions (such as indices:admin/index\_template/put and other…

---

## [Netflow Data Not Seen in ElasticSearch Dashboard](https://forum.elastiflow.com/t/netflow-data-not-seen-in-elasticsearch-dashboard/212)

<div class="topic-metadata">

**Author:** [@tallguy86](https://forum.elastiflow.com/u/tallguy86)\
**Replies:** 1\
**Last updated:** [January 10, 2025, 4:33pm UTC](https://forum.elastiflow.com/t/netflow-data-not-seen-in-elasticsearch-dashboard/212 "2025-01-10T16:33:08Z")

</div>

Problem description: After installing and configuring ElasticFlow and ElasticSearch/Kibana, data not seen in ElasticSearch Dashboard. Please let me know if I am missing steps or configuration as I am lost. Followed co…

---

## [Upgraded to 7.5.2 and now can't ingest flows or start without errors](https://forum.elastiflow.com/t/upgraded-to-7-5-2-and-now-cant-ingest-flows-or-start-without-errors/206)

<div class="topic-metadata">

**Author:** [@MikeH](https://forum.elastiflow.com/u/MikeH)\
**Replies:** 1\
**Last updated:** [December 5, 2024, 4:28pm UTC](https://forum.elastiflow.com/t/upgraded-to-7-5-2-and-now-cant-ingest-flows-or-start-without-errors/206 "2024-12-05T16:28:35Z")

</div>

When I upgraded the flowconf.yml file was replaced so I had to relicense the instance. Now I can’t get the system to ingest flows. Here is the output of systemctl status flowcoll.service ● flowcoll.service - ElastiFlo…

---

## [IP drop in flow collector options](https://forum.elastiflow.com/t/ip-drop-in-flow-collector-options/204)

<div class="topic-metadata">

**Author:** [@jimmy.leriane](https://forum.elastiflow.com/u/jimmy.leriane)\
**Replies:** 1\
**Last updated:** [November 30, 2024, 3:53pm UTC](https://forum.elastiflow.com/t/ip-drop-in-flow-collector-options/204 "2024-11-30T15:53:13Z")

</div>

Hi, Is there any option or specific way to drop IP?, such as using a Logstash filter to drop recordings of certain source or destination IPs in flows, I wanna to collect specific IP in cluster. Is there any way to do th…

---

## [Snmpcoll unable to find device](https://forum.elastiflow.com/t/snmpcoll-unable-to-find-device/181)

<div class="topic-metadata">

**Author:** [@jvusos](https://forum.elastiflow.com/u/jvusos)\
**Replies:** 17\
**Last updated:** [November 22, 2024, 3:34pm UTC](https://forum.elastiflow.com/t/snmpcoll-unable-to-find-device/181 "2024-11-22T15:34:34Z")

</div>

Hi I have a problem with snmp standard license. i have this message on snmpcoll.log ’ 2024-10-03T16:03:34.683+1100 info snmp.controller.opmanager opmanager/opmanager.go:95 initiating device polling …

---

## [Community license error token is expired](https://forum.elastiflow.com/t/community-license-error-token-is-expired/195)

<div class="topic-metadata">

**Author:** [@GCSTech](https://forum.elastiflow.com/u/GCSTech)\
**Replies:** 1\
**Last updated:** [November 15, 2024, 11:34am UTC](https://forum.elastiflow.com/t/community-license-error-token-is-expired/195 "2024-11-15T11:34:54Z")

</div>

I am running the community edition and this morning it is not running with the following error. exiting because of a license error token is expired by 11h11m11.286558158s How do I renew the community license as there i…

---

## [Enrichment using NETIF\_SNMP\_ACCESS not working?](https://forum.elastiflow.com/t/enrichment-using-netif-snmp-access-not-working/189)

<div class="topic-metadata">

**Author:** [@Surge](https://forum.elastiflow.com/u/Surge)\
**Replies:** 2\
**Last updated:** [November 1, 2024, 1:20pm UTC](https://forum.elastiflow.com/t/enrichment-using-netif-snmp-access-not-working/189 "2024-11-01T13:20:42Z")

</div>

How is NETIF\_SNMP\_ACCESS supposed to work with NetObserv Flow? Where can I find documentation for the file format and options? I set the following but never see any SNMP queries from the collector: EF\_PROCESSOR\_ENRICH\_…

---

## [Fortigate vendor detected application data garbled characters](https://forum.elastiflow.com/t/fortigate-vendor-detected-application-data-garbled-characters/190)

<div class="topic-metadata">

**Author:** [@Surge](https://forum.elastiflow.com/u/Surge)\
**Replies:** 8\
**Last updated:** [November 6, 2024, 1:05pm UTC](https://forum.elastiflow.com/t/fortigate-vendor-detected-application-data-garbled-characters/190 "2024-11-06T13:05:54Z")

</div>

Is there some sort of character encoding issue with the Fortigate application data? Is there a way to fix or normalize the data on the Elastiflow flow collector? Running Elastiflow NetObserv 7.4 and FortiOS 7.4.4

---

## [No data in dashboard](https://forum.elastiflow.com/t/no-data-in-dashboard/185)

<div class="topic-metadata">

**Author:** [@Rodney](https://forum.elastiflow.com/u/Rodney)\
**Replies:** 2\
**Last updated:** [October 28, 2024, 11:29am UTC](https://forum.elastiflow.com/t/no-data-in-dashboard/185 "2024-10-28T11:29:42Z")

</div>

i followed the following guide to setup elastiflow under docker\_install: GitHub - elastiflow/ElastiFlow-Tools: Script to easily install ElastiFlow for ElasticSearch with all dependencies after the setup is finished, i c…

[Previous page](https://forum.elastiflow.com/c/community/4.md)

[Next page](https://forum.elastiflow.com/c/community/4.md?page=2)
