-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Locality values mismatch between Netflow input and ingest pipeline #24272
Comments
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
To clarify the issue: The Netflow input will set locality fields to one of two possible values: beats/x-pack/filebeat/input/netflow/convert.go Lines 385 to 388 in 6986c84
The Netflow module ingest pipeline uses those values to set beats/x-pack/filebeat/module/netflow/log/ingest/pipeline.yml Lines 54 to 73 in 6986c84
We need to choose which pair of values to use, private/public or internal/external. |
In addition to the mismatch of values, there is another bug that could be at play #24110 since this would cause there to be no default value for internal_networks CIDRs. |
Changes netflow input to use internal and external for locality fields: - source.locality - destination.locality - flow.locality Previously it was using public and private. Fixes #24272
Changes netflow input to use internal and external for locality fields: - source.locality - destination.locality - flow.locality Previously it was using public and private. Fixes elastic#24272 (cherry picked from commit 0c6acc9)
Changes netflow input to use internal and external for locality fields: - source.locality - destination.locality - flow.locality Previously it was using public and private. Fixes elastic#24272 (cherry picked from commit 0c6acc9)
elastic#24461) Changes netflow input to use internal and external for locality fields: - source.locality - destination.locality - flow.locality Previously it was using public and private. Fixes elastic#24272 (cherry picked from commit a1a8d7a)
For confirmed bugs, please report:
Netflow input will populate {source,destination,flow}.locality fields with values either
private
orpublic
, depending on theinternal_networks
configuration option.The ingest pipeline for the netflow module uses those fields to populate
network.direction
. However, it is expecting the values to beinternal
orexternal
, which causesnetwork.direction
to always beunknown
.The text was updated successfully, but these errors were encountered: