Hi
I have just installed graylog and was exploring its netflow feature. i have added input for netflow but its not shoing any data. when i checked in the linux shell the output says its listening on port 2055 but seems like its not listening on ipv4 ?
greylog@greylog:~$ netstat -tunlp
(Not all processes could be identified, non-owned process info
will not be shown, you would have to be root to see it all.)
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 127.0.0.1:27017 0.0.0.0:* LISTEN -
tcp 0 0 127.0.0.53:53 0.0.0.0:* LISTEN -
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN -
tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN -
tcp6 0 0 10.20.6.98:9000 :::* LISTEN -
tcp6 0 0 :::22 :::* LISTEN -
udp 0 0 127.0.0.53:53 0.0.0.0:* -
udp 0 0 10.20.6.98:68 0.0.0.0:* -
udp6 0 0 10.20.6.98:2055 :::* -
udp6 0 0 10.20.6.98:2055 :::* -
udp6 0 0 10.20.6.98:2055 :::* -
udp6 0 0 10.20.6.98:2055 :::* -
udp6 0 0 10.20.6.98:514 :::* -
udp6 0 0 10.20.6.98:514 :::* -
udp6 0 0 10.20.6.98:514 :::* -
udp6 0 0 10.20.6.98:514 :::* -
Please if someone can guide me ?
I have configured netflow exports from mikrotik using v5 … tried v9 and ipfix as well. couldnt get data via any version.