I’m exporting Netflow v9 from Pfsense to Graylog through softflowd package. Everything is working but the sort option.
I’m trying to get the last hour TOP Talkers summary (sum of nf_bytes).
This will allow me to check who is the TOP Talker in that given hour and show the respective peer.
If I use the sort options such as, timestamp descending and nf_bytes descending at the same time, the second one doesn’t work… I have to use one or the other but both not at the same time.
System: Raspberry Pi 4B Ubuntu 20.04.6 LTS 64 bits running: Graylog 5.0.6 | Mongodb 6.0.5 | ElasticSearch 7.10.2
Mixing timestamp and MB (nf_bytes) sort options:
As you can see above, timestamp is working but the second sort MB (nf_bytes) is not.
Only the first sort option chosen works based on my testing and second one is ignored.
I tried to the pin columns, I tried to remove the widget and recreate it again, even cleared the elasticsearch database but nothing seems to work…
I wonder if I’m doing something wrong, or if this is perhaps a bug in the sort option.
Any tips to make this work?
Thanks