HELP: Injecting PCAP to ELK

(Nuggetinu) #1

I have an access point from which I would like to capture traffic and visualize it through ELK. I am collecting traffic from the AP by using plink.exe on Windows to ssh the AP and running tcp dump on the AP outputting to a pcap file. I have installed ELK on Windows since I'm more familiar with Windows. Next step is to inject the pcap data to ELK. Do you know of some good methods to do this please?

Thanks in advance!

(Mark Walkom) #2

Please don't cross post the same question :slight_smile: Best way to put pcap traffic into logstash/Elasticsearch

(Mark Walkom) #3