# CPU footprint of packetbeat is high

**URL:** <https://discuss.elastic.co/t/cpu-footprint-of-packetbeat-is-high/31553>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [October 2, 2015, 4:00pm UTC](https://discuss.elastic.co/t/cpu-footprint-of-packetbeat-is-high/31553 "2015-10-02T16:00:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![5uraj](https://avatars.discourse-cdn.com/v4/letter/5/fbc32d/32.png) [@5uraj](https://discuss.elastic.co/u/5uraj)\
**Post date:** [October 2, 2015, 4:00pm UTC](https://discuss.elastic.co/t/cpu-footprint-of-packetbeat-is-high/31553/1 "2015-10-02T16:00:06Z")

</div>

I am using packetbeat in af\_paket traffic capturing mode, which give me about 30% CPU footprint on single core instance when I go for http and mysql monitoring only. As soon as I increase more header and cookie capture in http, CPU goes a little bit higher.

I am getting lots of "WARN Response from unknown transaction. Ignoring" warnings too, looks like packetbeat ignores already established connection's communication.

I am unable to find any documentation which can help me in setting up a dedicated server for packetbeat and how can I forward traffic from application servers to packetbeat instance.  
Would be great if you guys can include this in documentation.

Packetbeat version info, I am using "1.0.0-beta3 (amd64)" on ubuntu 14.04.

Thanks,  
Suraj

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [October 4, 2015, 7:41pm UTC](https://discuss.elastic.co/t/cpu-footprint-of-packetbeat-is-high/31553/2 "2015-10-04T19:41:13Z")

</div>

How many requests per second / packets per second are you seeing?

Indeed we should have some docs about installing a dedicate Packetbeat server. In short, I'd recommend installing a supported Linux distribution (recent ubuntu/debian or centos/redhat version) and then Packetbeat on top using `af_packet`.

How you forward the traffic depends on your infrastructure. Usually the easiest is to use the port mirroring functionality of your switches.

Let us know if you have specific questions.

---

<div class="post-metadata">

**Author:** ![5uraj](https://avatars.discourse-cdn.com/v4/letter/5/fbc32d/32.png) [@5uraj](https://discuss.elastic.co/u/5uraj)\
**Post date:** [October 5, 2015, 6:50am UTC](https://discuss.elastic.co/t/cpu-footprint-of-packetbeat-is-high/31553/3 "2015-10-05T06:50:09Z")

</div>

Tudor,

We are running instances in AWS EC2, in terms of traffic we are getting about 100 rps.  
Not sure whether port mirroring is a good Idea as it will consume extra bandwidth and doing port mirroring on EC2 is pretty complicated.  
So it'll be great if we can reduce CPU footprint of Packetbeat as newrelic does it so smoothly.

Thanks,  
Suraj

---

<div class="post-metadata">

**Author:** ![dickepa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dickepa/32/8069_2.png) [@dickepa](https://discuss.elastic.co/u/dickepa)\
**Post date:** [May 13, 2016, 3:41pm UTC](https://discuss.elastic.co/t/cpu-footprint-of-packetbeat-is-high/31553/4 "2016-05-13T15:41:52Z")

</div>

Any updates on this anyone?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:52pm UTC](https://discuss.elastic.co/t/cpu-footprint-of-packetbeat-is-high/31553/5 "2017-07-05T21:52:00Z")

</div>


