# Getting deeper into NFS with Packetbeat

**URL:** <https://discuss.elastic.co/t/getting-deeper-into-nfs-with-packetbeat/179124>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [April 30, 2019, 4:55pm UTC](https://discuss.elastic.co/t/getting-deeper-into-nfs-with-packetbeat/179124 "2019-04-30T16:55:24Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![databloom](https://avatars.discourse-cdn.com/v4/letter/d/ea5d25/32.png) [@databloom](https://discuss.elastic.co/u/databloom)\
**Post date:** [April 30, 2019, 4:55pm UTC](https://discuss.elastic.co/t/getting-deeper-into-nfs-with-packetbeat/179124/1 "2019-04-30T16:55:25Z")

</div>

Hi !

Love packetbeat, I'm using it to replace home-grown sed and awk templates with tshark. I looked through fields.yml and ran packetbeat -d and realized you were constraining your output event schema predump.

Is it possible for you folks to provide the points where libpcap / packetbeat -d control point are and how they spits out raw parsable pcap telemetry and where your events are defined ?

Very interested in capturing this type of granularity:

tshark -V -r classifier-training-001-resnet-50.pcap -T pdml

Here's my list of dream events coming out of my pcap pipeline:

nfs.access\_check  
nfs.access\_delete  
nfs.access\_execute  
nfs.access\_extend  
nfs.access\_lookup  
nfs.access\_modify  
nfs.access\_read  
nfs.access\_rights  
nfsacl.procedure\_v3  
nfs.atime  
nfs.atime  
nfs.atime  
nfs.atime.nsec  
nfs.atime.nsec  
nfs.atime.nsec  
nfs.atime.sec  
nfs.atime.sec  
nfs.atime.sec  
nfs.attr  
nfs.attr\_count  
nfs.attributes\_follow  
nfs.attributes\_follow  
nfs.attr\_mask  
nfs.clientid  
nfs.cookie3  
nfs.count3  
nfs.count3\_dircount  
nfs.count3\_maxcount  
nfs.ctime  
nfs.ctime  
nfs.ctime  
nfs.ctime.nsec  
nfs.ctime.nsec  
nfs.ctime.nsec  
nfs.ctime.sec  
nfs.ctime.sec  
nfs.ctime.sec  
nfs.data  
nfs.dtime  
nfs.dtime.nsec  
nfs.dtime.sec  
nfs.fattr3.fileid  
nfs.fattr3.fileid  
nfs.fattr3.fileid  
nfs.fattr3.fsid  
nfs.fattr3.fsid  
nfs.fattr3.fsid  
nfs.fattr3.gid  
nfs.fattr3.gid  
nfs.fattr3.gid  
nfs.fattr3.nlink  
nfs.fattr3.nlink  
nfs.fattr3.nlink  
nfs.fattr3.size  
nfs.fattr3.size  
nfs.fattr3.size  
nfs.fattr3.type  
nfs.fattr3.type  
nfs.fattr3.type  
nfs.fattr3.uid  
nfs.fattr3.uid  
nfs.fattr3.uid  
nfs.fattr3.used  
nfs.fattr3.used  
nfs.fattr3.used  
nfs.fattr4.files\_avail  
nfs.fattr4.files\_free  
nfs.fattr4.files\_total  
nfs.fattr4.space\_avail  
nfs.fattr4.space\_free  
nfs.fattr4.space\_total  
nfs.fhandle  
nfs.fhandle  
nfs.fhandle  
nfs.fh.hash  
nfs.fh.hash  
nfs.fh.hash  
nfs.fh.length  
nfs.fh.length  
nfs.fh.length  
nfs.fsinfo.dtpref  
nfs.fsinfo.maxfilesize  
nfs.fsinfo.properties  
nfs.fsinfo.properties.hardlinks  
nfs.fsinfo.properties.pathconf  
nfs.fsinfo.properties.setattr  
nfs.fsinfo.properties.symlinks  
nfs.fsinfo.rtmax  
nfs.fsinfo.rtmult  
nfs.fsinfo.rtpref  
nfs.fsinfo.wtmax  
nfs.fsinfo.wtmult  
nfs.fsinfo.wtpref  
nfs.fsstat3\_resok.abytes  
nfs.fsstat3\_resok.afiles  
nfs.fsstat3\_resok.fbytes  
nfs.fsstat3\_resok.ffiles  
nfs.fsstat3\_resok.tbytes  
nfs.fsstat3\_resok.tfiles  
nfs.fsstat.invarsec  
nfs.handle\_follow  
nfs.main\_opcode  
nfs.minorversion  
nfs.mode3  
nfs.mode3  
nfs.mode3  
nfs.mode3.rgrp  
nfs.mode3.rgrp  
nfs.mode3.rgrp  
nfs.mode3.roth  
nfs.mode3.roth  
nfs.mode3.roth  
nfs.mode3.rusr  
nfs.mode3.rusr  
nfs.mode3.rusr  
nfs.mode3.sgid  
nfs.mode3.sgid  
nfs.mode3.sgid  
nfs.mode3.sticky  
nfs.mode3.sticky  
nfs.mode3.sticky  
nfs.mode3.suid  
nfs.mode3.suid  
nfs.mode3.suid  
nfs.mode3.wgrp  
nfs.mode3.wgrp  
nfs.mode3.wgrp  
nfs.mode3.woth  
nfs.mode3.woth  
nfs.mode3.woth  
nfs.mode3.wusr  
nfs.mode3.wusr  
nfs.mode3.wusr  
nfs.mode3.xgrp  
nfs.mode3.xgrp  
nfs.mode3.xgrp  
nfs.mode3.xoth  
nfs.mode3.xoth  
nfs.mode3.xoth  
nfs.mode3.xusr  
nfs.mode3.xusr  
nfs.mode3.xusr  
nfs.mtime  
nfs.mtime  
nfs.mtime  
nfs.mtime.nsec  
nfs.mtime.nsec  
nfs.mtime.nsec  
nfs.mtime.sec  
nfs.mtime.sec  
nfs.mtime.sec  
nfs.name  
nfs.nfsstat4  
nfs.nfsstat4  
nfs.offset3  
nfs.opcode  
nfs.ops.count  
nfs.pathconf.case\_insensitive  
nfs.pathconf.case\_preserving  
nfs.pathconf.chown\_restricted  
nfs.pathconf.linkmax  
nfs.pathconf.name\_max  
nfs.pathconf.no\_trunc  
nfs.procedure\_v3  
nfs.procedure\_v4  
nfs.readdir.entry  
nfs.readdir.eof  
nfs.readdirplus.entry.cookie  
nfs.readdirplus.entry.fileid  
nfs.readdirplus.entry.name  
nfs.read.eof  
nfs.specdata1  
nfs.specdata1  
nfs.specdata1  
nfs.specdata2  
nfs.specdata2  
nfs.specdata2  
nfs.status  
nfs.status  
nfs.status3  
nfs.tag  
nfs.verifier

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 3, 2019, 1:32pm UTC](https://discuss.elastic.co/t/getting-deeper-into-nfs-with-packetbeat/179124/2 "2019-05-03T13:32:23Z")

</div>

> [@databloom](#):
>
> Is it possible for you folks to provide the points where libpcap / packetbeat -d control point are and how they spits out raw parsable pcap telemetry and where your events are defined ?

The code that is responsible for decoding the NFS protocol data is contained in this package [https://github.com/elastic/beats/tree/master/packetbeat/protos/nfs](https://github.com/elastic/beats/tree/master/packetbeat/protos/nfs). This code is independent of the code that captures the data via libpcap or afpacket. The traffic capturing code is in the [sniffer](https://github.com/elastic/beats/tree/master/packetbeat/sniffer) package.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2019, 1:32pm UTC](https://discuss.elastic.co/t/getting-deeper-into-nfs-with-packetbeat/179124/3 "2019-05-31T13:32:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
