# Can Packetbeat just capture the packets without decoding?

**URL:** <https://discuss.elastic.co/t/can-packetbeat-just-capture-the-packets-without-decoding/323473>\
**Category:** Beats\
**Tags:** beats-module, packetbeat\
**Created:** [January 19, 2023, 5:59am UTC](https://discuss.elastic.co/t/can-packetbeat-just-capture-the-packets-without-decoding/323473 "2023-01-19T05:59:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sarathtv](https://avatars.discourse-cdn.com/v4/letter/s/d07c76/32.png) [@sarathtv](https://discuss.elastic.co/u/sarathtv)\
**Post date:** [January 19, 2023, 5:59am UTC](https://discuss.elastic.co/t/can-packetbeat-just-capture-the-packets-without-decoding/323473/1 "2023-01-19T05:59:00Z")

</div>

My application uses SIP protocol and I wanted to have a real-time packet analyzer for it. I found that Packetbeat could be the perfect fit, but unfortunately it doesn't support SIP in the listed set of protocols.  
Is there any way in which I can still capture the packets using the Packetbeat in the binary form and then write to a file/kafka which I can later pick up and decode, without modifying the source code of Packetbeat?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 19, 2023, 6:18am UTC](https://discuss.elastic.co/t/can-packetbeat-just-capture-the-packets-without-decoding/323473/2 "2023-01-19T06:18:32Z")

</div>

Welcome to our community! 😃

There's not, no. You could try using a TCP input like [this one](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-tcp.html).

---

<div class="post-metadata">

**Author:** ![sarathtv](https://avatars.discourse-cdn.com/v4/letter/s/d07c76/32.png) [@sarathtv](https://discuss.elastic.co/u/sarathtv)\
**Post date:** [January 19, 2023, 6:36am UTC](https://discuss.elastic.co/t/can-packetbeat-just-capture-the-packets-without-decoding/323473/3 "2023-01-19T06:36:24Z")

</div>

Thank you 🙂 appreciate the quick reply.

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [January 24, 2023, 2:37pm UTC](https://discuss.elastic.co/t/can-packetbeat-just-capture-the-packets-without-decoding/323473/4 "2023-01-24T14:37:28Z")

</div>

@sarathtv Packetbeat provides some support for SIP data. Curious if the fields here would meet your needs? [SIP fields | Packetbeat Reference [8.6] | Elastic](https://www.elastic.co/guide/en/beats/packetbeat/8.6/exported-fields-sip.html)

---

<div class="post-metadata">

**Author:** ![sarathtv](https://avatars.discourse-cdn.com/v4/letter/s/d07c76/32.png) [@sarathtv](https://discuss.elastic.co/u/sarathtv)\
**Post date:** [January 25, 2023, 4:35am UTC](https://discuss.elastic.co/t/can-packetbeat-just-capture-the-packets-without-decoding/323473/5 "2023-01-25T04:35:05Z")

</div>

Oh, that's awesome! I guess SIP was not there, when I last checked the documentation. This would suffice my needs regarding SIP. Also, the other point that warkolm mentioned also remains true that I can't use it just for capturing purpose for any other unsupported protocols in binary form. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 22, 2023, 6:35am UTC](https://discuss.elastic.co/t/can-packetbeat-just-capture-the-packets-without-decoding/323473/6 "2023-02-22T06:35:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
