NetFlow Optimizer send data over UDP protocol in syslog or JSON format which makes it easy to ingest into Elasticsearch, using Filebeat or Logstash or both.
Important: configure NFO output format as JSON
Filebeat has a small footprint and enables you to ship your flow data to Elasticsearch securely and reliably. Please note that Filebeat cannot add calculated fields at index time, and Logstash can be used with Filebeat if this is required. The steps below describe NFO -> Filebeat -> Elasticsearch - Kibana scenario.