# Does it support the collection of UDP traffic on the specified port number?

**URL:** <https://discuss.elastic.co/t/does-it-support-the-collection-of-udp-traffic-on-the-specified-port-number/270521>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [April 19, 2021, 12:43am UTC](https://discuss.elastic.co/t/does-it-support-the-collection-of-udp-traffic-on-the-specified-port-number/270521 "2021-04-19T00:43:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![angelyouyou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angelyouyou/32/87285_2.png) [@angelyouyou](https://discuss.elastic.co/u/angelyouyou)\
**Post date:** [April 19, 2021, 12:43am UTC](https://discuss.elastic.co/t/does-it-support-the-collection-of-udp-traffic-on-the-specified-port-number/270521/1 "2021-04-19T00:43:59Z")

</div>

Does it support the collection of UDP traffic on the specified port number?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 19, 2021, 12:48am UTC](https://discuss.elastic.co/t/does-it-support-the-collection-of-udp-traffic-on-the-specified-port-number/270521/2 "2021-04-19T00:48:05Z")

</div>

Hi @angelyouyou welcome to the community.

Can you be more specific which "it" for collecting UDP traffic are you referring to ?

Filebeat, packetbeat, Logstash?

We can probably help if you are more specific with your question.

Packetbeat is a Layer 7 Capture mechanism

Packetbeat works by capturing the network traffic between your application servers, decoding the application layer protocols (HTTP, MySQL, Redis, and so on), correlating the requests with the responses, and recording the interesting [fields](https://www.elastic.co/guide/en/beats/packetbeat/current/exported-fields.html) for each transaction.

So the answer is no it listens at a device level... however you can filter on

`network.transport` (tcp/udp) and / or `source.port` and `destination.port` if so desired.

See Exported fields [here](https://www.elastic.co/guide/en/beats/packetbeat/current/exported-fields-ecs.html)

So you could filter and only record those data.

Filebeat can capture raw UDP Packes on Particular Ports see [Here](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-udp.html)

---

<div class="post-metadata">

**Author:** ![angelyouyou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angelyouyou/32/87285_2.png) [@angelyouyou](https://discuss.elastic.co/u/angelyouyou)\
**Post date:** [April 26, 2021, 12:57pm UTC](https://discuss.elastic.co/t/does-it-support-the-collection-of-udp-traffic-on-the-specified-port-number/270521/3 "2021-04-26T12:57:10Z")

</div>

I want to get the UDP traffic information(pps/bps, not the contents) of the specified port for display. I guess it means packetbeat.  
Is there any way to get this statistic (bps/pps) count bu Filebeat, packetbeat or Logstash?  
Thanks very much for your help.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 26, 2021, 10:29pm UTC](https://discuss.elastic.co/t/does-it-support-the-collection-of-udp-traffic-on-the-specified-port-number/270521/4 "2021-04-26T22:29:05Z")

</div>

Hi @angelyouyou

I am looking but I do not think metricbeat or packetbeat capture exactly what you want.

metribeat capture I/O in total bytes and packets which can then be converted to bps and pps at an network interface level using the network module. It does not capture at the port level.

packetbeat captures the Bytes and Packets for flows so it it is the total bytes and packets per flow and a flow has a duration so it is not really bps or pps either.

Perhap take a look at the new socket auditbeat module [here](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-dataset-system-socket.html) for linux systems.

---

<div class="post-metadata">

**Author:** ![angelyouyou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angelyouyou/32/87285_2.png) [@angelyouyou](https://discuss.elastic.co/u/angelyouyou)\
**Post date:** [May 1, 2021, 7:05am UTC](https://discuss.elastic.co/t/does-it-support-the-collection-of-udp-traffic-on-the-specified-port-number/270521/5 "2021-05-01T07:05:54Z")

</div>

> [@stephenb](#):
>
> socket auditbeat module

I think socket auditbeat module meets my usage.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 29, 2021, 9:06am UTC](https://discuss.elastic.co/t/does-it-support-the-collection-of-udp-traffic-on-the-specified-port-number/270521/6 "2021-05-29T09:06:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
