I'm investigating network flows. And Packetbeat collect network traffic including forwarding.
I found some flow's destination is port 80 for http.
Otherwise, some flows source port is port 80.
I'm very sure the port 80 must be destination.
At this point, how does Packetbeat determine source and destination?
How can we solve this issue?
Thank you in advance,