# About extends a new protocol

**URL:** <https://discuss.elastic.co/t/about-extends-a-new-protocol/75152>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [February 15, 2017, 7:28am UTC](https://discuss.elastic.co/t/about-extends-a-new-protocol/75152 "2017-02-15T07:28:40Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jerome\_tan](https://avatars.discourse-cdn.com/v4/letter/j/97f17d/32.png) [@jerome\_tan](https://discuss.elastic.co/u/jerome_tan)\
**Post date:** [February 15, 2017, 7:28am UTC](https://discuss.elastic.co/t/about-extends-a-new-protocol/75152/1 "2017-02-15T07:28:40Z")

</div>

I am extending a new packetbeat, just wondering that the beat can bind and listen a port, if it can get the inbound and outbound byte via the port. i.e.: while listening to a HTTP port like 80, can we get the HTTP request and HTML code in the beat?

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [February 15, 2017, 11:16am UTC](https://discuss.elastic.co/t/about-extends-a-new-protocol/75152/2 "2017-02-15T11:16:24Z")

</div>

Not sure I understand, do you want to add a new protocol in Packetbeat that is based on HTTP?

Or do you want to actually accept TCP connections in Packetbeat? In the latter case, it's better to create a new beat for that.

More details about what you're trying to accomplish would be helpful.

---

<div class="post-metadata">

**Author:** ![jerome\_tan](https://avatars.discourse-cdn.com/v4/letter/j/97f17d/32.png) [@jerome\_tan](https://discuss.elastic.co/u/jerome_tan)\
**Post date:** [February 15, 2017, 11:23am UTC](https://discuss.elastic.co/t/about-extends-a-new-protocol/75152/3 "2017-02-15T11:23:00Z")

</div>

Actually, we are going to audit the data flow in our data platform, e.g.: we gotta monitor how many bytes send to client side by a SQL request(maybe not a SQL query but a FTP request). Like:

SQL query "select \* from XXX" returns 500Bytes data. FTP request "dump.zip" returns 100M bytes.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [February 15, 2017, 11:44am UTC](https://discuss.elastic.co/t/about-extends-a-new-protocol/75152/4 "2017-02-15T11:44:44Z")

</div>

Ok, I think the SQL part should be possible already with Packetbeat for mysql & postgresql. An FTP protocol would be interesting to add to PB.

---

<div class="post-metadata">

**Author:** ![jerome\_tan](https://avatars.discourse-cdn.com/v4/letter/j/97f17d/32.png) [@jerome\_tan](https://discuss.elastic.co/u/jerome_tan)\
**Post date:** [February 15, 2017, 1:02pm UTC](https://discuss.elastic.co/t/about-extends-a-new-protocol/75152/5 "2017-02-15T13:02:50Z")

</div>

I didn't really go thru the code of mysql etc.. I tested the HTTP protocol, the beat can only capture the inbound request, not the outbound response.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2017, 1:02pm UTC](https://discuss.elastic.co/t/about-extends-a-new-protocol/75152/6 "2017-03-15T13:02:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
