# Drop events to monitoring FTP

**URL:** <https://discuss.elastic.co/t/drop-events-to-monitoring-ftp/84443>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [May 3, 2017, 5:31pm UTC](https://discuss.elastic.co/t/drop-events-to-monitoring-ftp/84443 "2017-05-03T17:31:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rschirin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rschirin/32/45283_2.png) [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Post date:** [May 3, 2017, 5:31pm UTC](https://discuss.elastic.co/t/drop-events-to-monitoring-ftp/84443/1 "2017-05-03T17:31:28Z")

</div>

Hi,  
I was trying to use Packetbeat to monitor network traffic of a FTP server. in a specific way, I was trying to log all the attempted connections on local port 21 and 22.  
Just to start I've enabled http protocol on port 21-22 with this code:

```
packetbeat.protocols.http:
  ports: [21, 22]

```

but I'm getting event from a lot of local ports.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 3, 2017, 8:37pm UTC](https://discuss.elastic.co/t/drop-events-to-monitoring-ftp/84443/2 "2017-05-03T20:37:11Z")

</div>

Packetbeat does not support the FTP protocol. See [https://www.elastic.co/guide/en/beats/packetbeat/current/packetbeat-overview.html](https://www.elastic.co/guide/en/beats/packetbeat/current/packetbeat-overview.html) for a list of supported protocols.

---

<div class="post-metadata">

**Author:** ![rschirin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rschirin/32/45283_2.png) [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Post date:** [May 3, 2017, 9:07pm UTC](https://discuss.elastic.co/t/drop-events-to-monitoring-ftp/84443/3 "2017-05-03T21:07:20Z")

</div>

perfectly correct, I knew that but the if I try to connect via ftp or sftp to a file transfer server I will generate TCP traffic that theoretically Packetbeat can sniff.

Do you think could be an idea to think up a support to FTP protocol?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 3, 2017, 9:08pm UTC](https://discuss.elastic.co/t/drop-events-to-monitoring-ftp/84443/4 "2017-05-03T21:08:36Z")

</div>

It's possible, it may not be difficult given the FTP protocol is pretty static (in regards to changes) too 🙂

---

<div class="post-metadata">

**Author:** ![rschirin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rschirin/32/45283_2.png) [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Post date:** [May 3, 2017, 9:13pm UTC](https://discuss.elastic.co/t/drop-events-to-monitoring-ftp/84443/5 "2017-05-03T21:13:02Z")

</div>

I guess you suggest to start from [NewProtocolGuide](https://www.elastic.co/guide/en/beats/packetbeat/current/new-protocol.html)

right?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 4, 2017, 3:02pm UTC](https://discuss.elastic.co/t/drop-events-to-monitoring-ftp/84443/6 "2017-05-04T15:02:23Z")

</div>

If you don't need application layer details about the traffic you could try using [flows](https://www.elastic.co/guide/en/beats/packetbeat/current/configuration-flows.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2017, 3:14pm UTC](https://discuss.elastic.co/t/drop-events-to-monitoring-ftp/84443/7 "2017-06-01T15:14:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
