tshark would be the best way to move with pcap files
The json generated may be not necessary ready to be bulked into ES latest versions, but i suggest you use logstash to clean the json before ingest it to ES.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.