ntopng can export both flows and alerts in Elastic according to the Elastic Common Schema (ECS) format. You can dump flows (not alerts) in Elastic starting ntopng with -F “es;<mapping type>;<idx name>;<es URL>;<http auth>”. For instance you can do ntopng -F “es;ntopng;ntopng-%%Y.%%m.%%d;http://localhost:9200/_bulk;” We do not advise to use Elastic as flow collector, as when the […]