Graylog don't save nflow data

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question.
Don’t forget to select tags to help index your topic!

1. Describe your incident:
first of all 1. graylog show me pkts:0 bytes:0


  1. also, i have in overview panel data from 28 jul to 31 jule, bot search export csv give me only 31 jul since 11:20 to now( i choose to all time in search)

  2. This is my event system : Cath up WIndows- : 56 hours

also i change default settings(shards,index) becouse disk consumption is 80GB on the 2 days, its very very bad

2. Describe your environment:

  • OS Information: Linux Debian 20.04 Vmware

  • Package Version: graylog 5.0

  • Service logs, configurations, and environment variables:

3. What steps have you already taken to try and solve the problem?
I return setting to default yml files and gui graylog

4. How can the community help?
Sorry, I’ll ask everything at once
I would like to change the settings so that 400GB is enough for me for a month, and I would also like to see the number of bytes in packets. Some things do show a lot of bytes, but not everywhere. I would also like to create a regular expression for a couple dozen IP addresses and ports and immediately request a report on this data. It is also desirable to see live which host consumes the most network traffic

Helpful Posting Tips: Tips for Posting Questions that Get Answers [Hold down CTRL and link on link to open tips documents in a separate tab]

hey @Andre4s1199

How did you setup Input for Netflow and what kind of device is send data to Graylog?

As for reducing the amount of data there are a coupel ways to acheve this. One way is to reduce the fileds not needed. This can be done with a pipeline. To be honest when I had mine working, it did produce a lot of data but I increased my volume size on Graylog.

Hi! Thanks for reply. now i get data on search. I use cisco asa 5520 for gw all network. I configure netflow … at the moment I want to get a report from some IP and ports, but their number is too large. What is the best thing for me to do? write a small regulatory mapping in the search bar, which means nf_dst_ipv4:[FROM TO] AND nf_dst_xlate_port:(some port)… Or dst_port:(20000-25000) and repeat the word or for future matches on all ports that interest me… or should I use a more elegant way? If so, how? I would also like you to include a diagram similar to what is on the main CISCO ASA server (top 10 hosts using traffic)

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.