I’ve noticed that periodically my Elastiflow ECS results when shown in Kibana will show “unknown” for an ASN’s name next to the ASN itself, while the MaxMind database on the same host reports the correct name. From what’s I’ve noticed, this occurs only with specific ASNs, meanwhile everything else populates without issue.
For example, you would generally expect a result of “ACME Inc (65534)” when viewing the AS traffic dashboard if the maxmind dashboard reports ACME Inc as the organization for AS65534, however the actual result in the dashboard shows as “unknown (65534)”.
Upgrading to flowcoll 7.20.0 doesn’t seem to resolve the issue either, which has me perplexed as to what exactly is occurring.
I’d greatly appreciate some assistance in tracking down the source of this somewhat niche issue, as the flowcoll logs don’t seem to give anything useful for ip or asn enrichment in terms of errors.
Very recent, freshly downloaded from the Maxmind site.
I did notice that your example has some added variables such as EF_PROCESSOR_ENRICH_ASN_PREF and EF_PROCESSOR_ENRICH_JOIN_ASN, should I be using these on flowcoll 7.20.0 as well?