# Configuring packetbeat to monitor traffic from remote server

**URL:** https://discuss.elastic.co/t/configuring-packetbeat-to-monitor-traffic-from-remote-server/54361
**Category:** Beats
**Tags:** packetbeat
**Created:** [June 30, 2016, 6:14am UTC](https://discuss.elastic.co/t/configuring-packetbeat-to-monitor-traffic-from-remote-server/54361 "2016-06-30T06:14:22Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![rresol](https://avatars.discourse-cdn.com/v4/letter/r/a9a28c/32.png) [@rresol](https://discuss.elastic.co/u/rresol)
#### Post date: [June 30, 2016, 6:14am UTC](https://discuss.elastic.co/t/configuring-packetbeat-to-monitor-traffic-from-remote-server/54361/1 "2016-06-30T06:14:23Z")

</div>

Hello everyone I am new to packetbeat . I wanted to monitor traffic on a remote host whose ip address is 192.168.0.122 . How should I configure so that I can monitor the traffic on ports 80 and 27017. Here is my configuration file but this is throwing error:  
Error creating sniffer: non-network bits set in "192.168.0.124/0"  
...fail!  
Here is my yaml file.  
############################# Sniffer #########################################

# Select the network interfaces to sniff the data. You can use the "any"

# keyword to sniff on all connected interfaces.

interfaces:  
device: any  
bpf\_filter: "net 192.168.0.122/0"

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [June 30, 2016, 10:49am UTC](https://discuss.elastic.co/t/configuring-packetbeat-to-monitor-traffic-from-remote-server/54361/2 "2016-06-30T10:49:55Z")

</div>

you somehow have to forward the traffic send to 192.168.0.122 to your sniffing machine. Is is normally done via port-forwarding in your switch or via network taps.

---

<div class="post-metadata">

### Author: ![rresol](https://avatars.discourse-cdn.com/v4/letter/r/a9a28c/32.png) [@rresol](https://discuss.elastic.co/u/rresol)
#### Post date: [June 30, 2016, 11:05am UTC](https://discuss.elastic.co/t/configuring-packetbeat-to-monitor-traffic-from-remote-server/54361/3 "2016-06-30T11:05:25Z")

</div>

The configuration will be the same as when it is while I have both packetbeat and app server running on the same machine ? or should I specifically add ip addresses when packetbeat and server are running on different servers.

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [July 1, 2016, 9:10am UTC](https://discuss.elastic.co/t/configuring-packetbeat-to-monitor-traffic-from-remote-server/54361/4 "2016-07-01T09:10:43Z")

</div>

when using port forwarding or taps, you normally will push all traffic into one interface. So, instead of using `device: any`, I would configure the device receiving all forwarded packets. e.g. `device: eth5`. If you need additional filtering is up to you (e.g. if tap is pushing traffic from multiple machines).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 21, 2016, 6:14am UTC](https://discuss.elastic.co/t/configuring-packetbeat-to-monitor-traffic-from-remote-server/54361/5 "2016-07-21T06:14:29Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
