Hi
Tekletsadik,
In OwlH we manage flow data directly from traffic listened over the network by the NIDS solutions we integrate as Fernando says, Suricata, Zeek.
We can collect Netflow from other devices and provide the flow info as events in ELK console. As this flow data is quite noisy, you should consider splitting this flow data into different index patterns to avoid creating a mess in the wazuh-index.
Please let us know if you need more details.
You can contact us using our slack channel.
OwlH Slack
OwlH is part of the Wazuh group/team.
Best regards,
Jose A Izquierdo