# Does not capture ICMP traffic

**URL:** <https://discuss.elastic.co/t/does-not-capture-icmp-traffic/80036>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [March 26, 2017, 9:59am UTC](https://discuss.elastic.co/t/does-not-capture-icmp-traffic/80036 "2017-03-26T09:59:28Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![korsdecaying](https://avatars.discourse-cdn.com/v4/letter/k/dbc845/32.png) [@korsdecaying](https://discuss.elastic.co/u/korsdecaying)\
**Post date:** [March 26, 2017, 9:59am UTC](https://discuss.elastic.co/t/does-not-capture-icmp-traffic/80036/1 "2017-03-26T09:59:28Z")

</div>

DNS traffic is displayed in Kiban, and ICMP is not present

```
 # /etc/packetbeat/packetbeat.yml
    packetbeat.interfaces.device: 1

packetbeat.protocols.dns:
  ports: [53]
  include_authorities: true
  include_additionals: true
  
  packetbeat.protocols.icmp:
  
output.elasticsearch:
  hosts: ["localhost:9200"]
```

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [March 26, 2017, 6:44pm UTC](https://discuss.elastic.co/t/does-not-capture-icmp-traffic/80036/2 "2017-03-26T18:44:19Z")

</div>

You need to enable ICMP by adding _enabled: true_ to the ICMP config section like this...

```
packetbeat.protocols.icmp:
  # Enable ICMPv4 and ICMPv6 monitoring. Default: false
  enabled: true

```

Rob

---

<div class="post-metadata">

**Author:** ![korsdecaying](https://avatars.discourse-cdn.com/v4/letter/k/dbc845/32.png) [@korsdecaying](https://discuss.elastic.co/u/korsdecaying)\
**Post date:** [March 26, 2017, 7:20pm UTC](https://discuss.elastic.co/t/does-not-capture-icmp-traffic/80036/3 "2017-03-26T19:20:10Z")

</div>

Thank you. I tried. I restarted the elastic packetbeat. Does not preserve

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 27, 2017, 6:58pm UTC](https://discuss.elastic.co/t/does-not-capture-icmp-traffic/80036/4 "2017-03-27T18:58:02Z")

</div>

It looks like the idendation is off in your config for icmp.

---

<div class="post-metadata">

**Author:** ![korsdecaying](https://avatars.discourse-cdn.com/v4/letter/k/dbc845/32.png) [@korsdecaying](https://discuss.elastic.co/u/korsdecaying)\
**Post date:** [March 29, 2017, 9:59am UTC](https://discuss.elastic.co/t/does-not-capture-icmp-traffic/80036/5 "2017-03-29T09:59:52Z")

</div>

Tell me please where you can turn it on?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 29, 2017, 4:35pm UTC](https://discuss.elastic.co/t/does-not-capture-icmp-traffic/80036/6 "2017-03-29T16:35:39Z")

</div>

> [@rcowart](#):
>
> ```auto
> packetbeat.protocols.icmp:
> # Enable ICMPv4 and ICMPv6 monitoring. Default: false
> enabled: true
> 
> ```

The config to enable ICMP is exactly what Rob gave above. If you continue to have problems please provide your complete config file.

---

<div class="post-metadata">

**Author:** ![korsdecaying](https://avatars.discourse-cdn.com/v4/letter/k/dbc845/32.png) [@korsdecaying](https://discuss.elastic.co/u/korsdecaying)\
**Post date:** [March 29, 2017, 5:56pm UTC](https://discuss.elastic.co/t/does-not-capture-icmp-traffic/80036/7 "2017-03-29T17:56:46Z")

</div>

I apologize. Here is the complete file

```
# /etc/packetbeat/packetbeat.yml
packetbeat.interfaces.device: 1
    packetbeat.protocols.dns:
      ports: [53]
      include_authorities: true
      include_additionals: true
      
      packetbeat.protocols.icmp:
      enabled: true
      
    output.elasticsearch:
      hosts: ["localhost:9200"]
```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 29, 2017, 6:21pm UTC](https://discuss.elastic.co/t/does-not-capture-icmp-traffic/80036/8 "2017-03-29T18:21:03Z")

</div>

The configuration file is YAML and indentation is critical to proper interpretation of the data. Try it like this:

```auto
packetbeat.interfaces.device: 1

packetbeat.protocols.dns:
  ports: [53]
  include_authorities: true
  include_additionals: true
      
packetbeat.protocols.icmp:
  enabled: true
      
output.elasticsearch:
  hosts: ["localhost:9200"]

```

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [March 29, 2017, 6:35pm UTC](https://discuss.elastic.co/t/does-not-capture-icmp-traffic/80036/9 "2017-03-29T18:35:53Z")

</div>

@andrewkroh was a little faster than me. For what it is worth I tested the results with improper indentation as @korsdecaying posted and confirmed that it will cause ICMP to not work as expected.

More about YAML indentation rules here...  
[http://yaml.org/spec/1.2/2009-07-21/spec.html#id2576668](http://yaml.org/spec/1.2/2009-07-21/spec.html#id2576668)

As you work with Elastic Stack you will likely use YAML in a lot of places. This include configuration files, but also things like Logstash dictionary files use by the _translate_ filter. It is definitely worth familiarizing yourself with the YAML basics.

Rob

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 30, 2017, 8:24am UTC](https://discuss.elastic.co/t/does-not-capture-icmp-traffic/80036/10 "2017-03-30T08:24:46Z")

</div>

beats add some features on top of YAML. See [Beats Config file format docs](https://www.elastic.co/guide/en/beats/libbeat/current/config-file-format.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 27, 2017, 8:25am UTC](https://discuss.elastic.co/t/does-not-capture-icmp-traffic/80036/11 "2017-04-27T08:25:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
