Graylog2/graylog2-server

Netflow plugin, tries to show ipv4 addresses in the message for ipv6 flows

Open

#6,076 建立於 2019年7月3日

在 GitHub 查看
 (0 留言) (0 反應) (1 負責人)Java (6,945 star) (1,032 fork)batch import
#Mbuggood first issuetriaged

描述

Redirecting netflow statistics directly to graylog using sysctl net.netflow.destination=ip:port and configuring an Netflow UDP input to process all the incoming stats.

Expected Behavior

In the message it should show source and destination ip.

Current Behavior

Only does so for ipv4

Possible Solution

Change toMessage to use either ipv4 or ipv6 header for the flow.

Steps to Reproduce (for bugs)

  1. Configure a flow accounting on a ipv6 enabled interface with netflow pointing to Graylog Netflow input
  2. Look for messages with null values for source and destination
  • Graylog Version: Graylog 3.0.2+1686930 on aac10c1cf381 (Oracle Corporation 1.8.0_212 on Linux 5.1.0)
  • Elasticsearch Version:
  • MongoDB Version:
  • Operating System:
  • Browser version:

貢獻者指南