We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Describe the enhancement:
IPv6 addresses are not copied to destination.ip and source.ip fields. As a consequence visualizations for ipv6 netflows "do not work".
destination.ip
source.ip
IPv4 addresses are correctly handled in convert.go#L190 and convert.go#L202.
A workaround at this moment is to modify netflow input like this:
input: processors: - copy_fields: when: has_fields: ['netflow.destination_ipv6_address'] fields: - from: netflow.destination_ipv6_address to: destination.ip - copy_fields: when: has_fields: ['netflow.source_ipv6_address'] fields: - from: netflow.source_ipv6_address to: source.ip
The text was updated successfully, but these errors were encountered:
Pinging @elastic/siem (Team:SIEM)
Sorry, something went wrong.
Pinging @elastic/security-external-integrations (Team:Security-External Integrations)
Successfully merging a pull request may close this issue.
Describe the enhancement:
IPv6 addresses are not copied to
destination.ip
andsource.ip
fields. As a consequence visualizations for ipv6 netflows "do not work".IPv4 addresses are correctly handled in convert.go#L190 and convert.go#L202.
A workaround at this moment is to modify netflow input like this:
The text was updated successfully, but these errors were encountered: