You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to SELKS
Is it possible to send NetFlow to the SELKS IDS? I don't see any collector service running.
How are people collecting data from multiple ESXi hosts, with standard vswitches, simultaneously?
Peter Manev
unread,
Nov 22, 2017, 4:12:40 AM11/22/17
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Rob Babb, SELKS
On Sat, Nov 18, 2017 at 3:23 AM, Rob Babb <rob....@gmail.com> wrote:
> Is it possible to send NetFlow to the SELKS IDS? I don't see any collector
> service running.
Yes - you can ship almost anything i think.
>
> How are people collecting data from multiple ESXi hosts, with standard
> vswitches, simultaneously?
I think you can use filebeat on the remote or local hosts to collect
the data and then ingest in ES.