# Documentation on adding new Packetbeat protocols

**URL:** <https://discuss.elastic.co/t/documentation-on-adding-new-packetbeat-protocols/141831>\
**Category:** Beats\
**Created:** [July 26, 2018, 6:15pm UTC](https://discuss.elastic.co/t/documentation-on-adding-new-packetbeat-protocols/141831 "2018-07-26T18:15:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![dhughes](https://avatars.discourse-cdn.com/v4/letter/d/7ab992/32.png) [@dhughes](https://discuss.elastic.co/u/dhughes)\
**Post date:** [July 26, 2018, 6:15pm UTC](https://discuss.elastic.co/t/documentation-on-adding-new-packetbeat-protocols/141831/1 "2018-07-26T18:15:34Z")

</div>

I'm looking for any documentation on the current packetbeat structure, as well as how to add new protocols ... if this exists. I've installed the project, compiled and tested a little. But other than just starting going through the code ... this would help.

Best I could find myself was just this placeholder:

[https://www.elastic.co/guide/en/beats/devguide/6.x/protocol-modules.html](https://www.elastic.co/guide/en/beats/devguide/6.x/protocol-modules.html)

- Thanks in advance -

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [July 26, 2018, 8:28pm UTC](https://discuss.elastic.co/t/documentation-on-adding-new-packetbeat-protocols/141831/2 "2018-07-26T20:28:56Z")

</div>

Hello @dhughes,

Sadly, we don't have specific doc to explain how to add new protocols to packetbeat.  
I think it would be easier to just look through an existing protocol, [UDP](https://github.com/elastic/beats/blob/master/packetbeat/protos/udp/udp.go) and [TCP](https://github.com/elastic/beats/blob/master/packetbeat/protos/tcp/tcp.go) are a good starting point.

---

<div class="post-metadata">

**Author:** ![dhughes](https://avatars.discourse-cdn.com/v4/letter/d/7ab992/32.png) [@dhughes](https://discuss.elastic.co/u/dhughes)\
**Post date:** [August 2, 2018, 1:15pm UTC](https://discuss.elastic.co/t/documentation-on-adding-new-packetbeat-protocols/141831/3 "2018-08-02T13:15:17Z")

</div>

Thanks much for the response. I lieu of any other writeup, I found this post [Packetbeat:How to add a new protocol?](https://discuss.elastic.co/t/packetbeat-how-to-add-a-new-protocol/48372/7) that describes some steps.

Specifically, what I'm looking to do is add a new protocol, that sits above UDP (i.e. application layer).

I don't find a good example to base off of then. I see a DNS UDP implementation but I don't think that this uses the plugin method that seems to be the prescribed way to go. If there's a better example of a protocol to use please indicate (UDP example, if it matters much as different from a protocol that sits above TCP such as HTTP ...)

Just a basic outline as to how to begin would be most helpful, such as in the post above.

Thanks again -

David H.

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [August 7, 2018, 2:31pm UTC](https://discuss.elastic.co/t/documentation-on-adding-new-packetbeat-protocols/141831/4 "2018-08-07T14:31:50Z")

</div>

@dhughes Not sure what you mean by _not using the plugin_ method? I've looked at [https://github.com/elastic/beats/blob/master/packetbeat/protos/dns/dns.go](https://github.com/elastic/beats/blob/master/packetbeat/protos/dns/dns.go) and It is a plugin?

---

<div class="post-metadata">

**Author:** ![dhughes](https://avatars.discourse-cdn.com/v4/letter/d/7ab992/32.png) [@dhughes](https://discuss.elastic.co/u/dhughes)\
**Post date:** [August 7, 2018, 3:04pm UTC](https://discuss.elastic.co/t/documentation-on-adding-new-packetbeat-protocols/141831/5 "2018-08-07T15:04:27Z")

</div>

Yes, you're right once I looked closer I see where the DNS protocol plugin definition was in dns.go, not dns\_udp.go.

We've implemented our own protocol and are working on parsing, and then on to creating transactions.

Thanks -

- David H.

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [August 7, 2018, 3:37pm UTC](https://discuss.elastic.co/t/documentation-on-adding-new-packetbeat-protocols/141831/6 "2018-08-07T15:37:17Z")

</div>

@dhughes what protocol you are trying to parse and would you be interested in contributing it back?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2018, 5:37pm UTC](https://discuss.elastic.co/t/documentation-on-adding-new-packetbeat-protocols/141831/7 "2018-09-04T17:37:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
