# Capture network traffic

**URL:** https://discuss.elastic.co/t/capture-network-traffic/309738
**Category:** Beats
**Tags:** filebeat, metricbeat
**Created:** [July 15, 2022, 1:14pm UTC](https://discuss.elastic.co/t/capture-network-traffic/309738 "2022-07-15T13:14:06Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![brkw](https://avatars.discourse-cdn.com/v4/letter/b/a587f6/32.png) [@brkw](https://discuss.elastic.co/u/brkw)
#### Post date: [July 15, 2022, 1:14pm UTC](https://discuss.elastic.co/t/capture-network-traffic/309738/1 "2022-07-15T13:14:06Z")

</div>

Hi all. I want to use ELk stack with beats to capture all traffic in my network. I installed ELK stack on VM and I want to capture all the traffic which goes in or out in my network. My configuration is set in this way: I have a span port on my firewall and my switch is connected to this port, after that traffic comes from switch to my NIC and this card is installed directly in the server where is my VM. The question is: when the traffic comes in this way to my server - that is layer 2 traffic from OSI model. Is it possible for Beats to capture layer 2 frames or what should I do to review this traffic, because it comes directly to my VM. Probably I need another tool to transform this traffic, but can you recommend me which one. Thank you in advance!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 12, 2022, 3:14pm UTC](https://discuss.elastic.co/t/capture-network-traffic/309738/2 "2022-08-12T15:14:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
