# Dest.stats vs Source.stats

**URL:** <https://discuss.elastic.co/t/dest-stats-vs-source-stats/100442>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [September 14, 2017, 3:00am UTC](https://discuss.elastic.co/t/dest-stats-vs-source-stats/100442 "2017-09-14T03:00:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![flowsys](https://avatars.discourse-cdn.com/v4/letter/f/a9a28c/32.png) [@flowsys](https://discuss.elastic.co/u/flowsys)\
**Post date:** [September 14, 2017, 3:00am UTC](https://discuss.elastic.co/t/dest-stats-vs-source-stats/100442/1 "2017-09-14T03:00:04Z")

</div>

How do we interpret in a document the value of **dest.stats.net\_packets\_total** vs **source.stats.net\_packets\_total**?  
Is it the total packets received at destination IP and total packets sent from source IP?

Or

Total packets sent to destination IP and total packets received from source IP?

Very confusing. Please help me to understand this.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [September 14, 2017, 12:08pm UTC](https://discuss.elastic.co/t/dest-stats-vs-source-stats/100442/2 "2017-09-14T12:08:21Z")

</div>

You can find the documentation here: [https://www.elastic.co/guide/en/beats/packetbeat/current/exported-fields-flows\_event.html](https://www.elastic.co/guide/en/beats/packetbeat/current/exported-fields-flows_event.html)

I agree it's somewhat confusing in the docs. The `source.stats` namespace contains metrics on event produced by the source. That is `source.stats.net_packets_total` is the total number of packets send by the `source.ip`. The `dest.stats.net_packets_total` is the total number of packets send by the `dest.ip`.

---

<div class="post-metadata">

**Author:** ![flowsys](https://avatars.discourse-cdn.com/v4/letter/f/a9a28c/32.png) [@flowsys](https://discuss.elastic.co/u/flowsys)\
**Post date:** [September 15, 2017, 1:58am UTC](https://discuss.elastic.co/t/dest-stats-vs-source-stats/100442/3 "2017-09-15T01:58:30Z")

</div>

So `dest.stats.net_packets_total` is the total packets sent by `dest.ip` ?

If the packets are sent by `dest.ip`, shouldn't it be recorded as `source.ip` since it is the "source".

In addition, in the packetbeat documents we can see some `source.ip` and `dest.ip` with the same IP.

How do we differentiate what is source and dest since `dest.ip` can be the one sending the packets too?

Confusing...

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 4, 2017, 10:15am UTC](https://discuss.elastic.co/t/dest-stats-vs-source-stats/100442/4 "2017-10-04T10:15:40Z")

</div>

> If the packets are sent by dest.ip, shouldn't it be recorded as source.ip since it is the "source".

As packetbeat collects stats for the biflow (stats in both directions) on can argue about naming in either direction. Here I'd say no, as IP and stats of packets produced by that IP should be stored in the same namespace (in this case `dest`).

The source and destination IPs (ports) are determined by the first packets seen. If IPs are the same, also check the port numbers.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 1, 2017, 10:15am UTC](https://discuss.elastic.co/t/dest-stats-vs-source-stats/100442/5 "2017-11-01T10:15:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
