# Auditbeat vs elastic endpoint for collecting network traffic from server

**URL:** <https://discuss.elastic.co/t/auditbeat-vs-elastic-endpoint-for-collecting-network-traffic-from-server/337253>\
**Category:** Endpoint Security\
**Created:** [June 30, 2023, 4:20am UTC](https://discuss.elastic.co/t/auditbeat-vs-elastic-endpoint-for-collecting-network-traffic-from-server/337253 "2023-06-30T04:20:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [June 30, 2023, 4:20am UTC](https://discuss.elastic.co/t/auditbeat-vs-elastic-endpoint-for-collecting-network-traffic-from-server/337253/1 "2023-06-30T04:20:41Z")

</div>

Hi all.  
I'm trying to migrate from auditbeat to elastic endpoint and most of every module is ok except for the network.  
I notice that elastic-endpoint connect network traffic a lot less that auditbeat.  
After some investigation i appear that elasitc-endpoint does not log traffic from other server that connect to the server via some process while auditbeat can do that.

Can someone explain to me how that work and how enable endpoint to collect the network traffic from other server connect to the endpoint as well.

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [June 30, 2023, 1:33pm UTC](https://discuss.elastic.co/t/auditbeat-vs-elastic-endpoint-for-collecting-network-traffic-from-server/337253/2 "2023-06-30T13:33:00Z")

</div>

Hi @lusynda!

Have you taken a look at the Elastic Agent Network integration? With this integration, it is possible to collect netflow and other network protocols for a better detailing of events.

Follow the link to this integration [Network Packet Capture | Elastic docs](https://docs.elastic.co/integrations/network_traffic)

You can also use the FIM integration for auditbeat migration:

> **[File Integrity Monitoring | Elastic docs](https://docs.elastic.co/integrations/fim)**
>
> The File Integrity Monitoring integration reports filesystem changes in real time.

---

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [July 3, 2023, 1:11pm UTC](https://discuss.elastic.co/t/auditbeat-vs-elastic-endpoint-for-collecting-network-traffic-from-server/337253/3 "2023-07-03T13:11:47Z")

</div>

After trying the network,  
i'm still feel like that is not like that with auditbeat.  
For ex:  
from 1 of the client i use telnet command to telnet the server on port 443.  
With auditbeat that traffic is loged successfully but with both endpoint and network integration that connection is not loged at all.

Is there a way to config the network to capture all traffic to the end server like that of auditbeat.

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [July 3, 2023, 7:42pm UTC](https://discuss.elastic.co/t/auditbeat-vs-elastic-endpoint-for-collecting-network-traffic-from-server/337253/4 "2023-07-03T19:42:47Z")

</div>

In the Network integration, did you enable the netflow function? In fact, for some auditing features, auditbeat is still the most recommended. Did you also enable FIM integration?

---

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [July 4, 2023, 1:25am UTC](https://discuss.elastic.co/t/auditbeat-vs-elastic-endpoint-for-collecting-network-traffic-from-server/337253/5 "2023-07-04T01:25:05Z")

</div>

> [@wsouza](#):
>
> In the Network integration, did you enable the netflow function?

I have enable the netflow function but still no good.

> [@wsouza](#):
>
> In fact, for some auditing features, auditbeat is still the most recommended.

What do you mean by this, i though endpoint was suppose to be better than auditbeat. Can you specified which part does auditbeat do better that elastic agent integrations.

> [@wsouza](#):
>
> Did you also enable FIM integration?

I'm trying it todays.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 1, 2023, 1:25am UTC](https://discuss.elastic.co/t/auditbeat-vs-elastic-endpoint-for-collecting-network-traffic-from-server/337253/6 "2023-08-01T01:25:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
