# How packetbeat determine source and destination in TCP flow?

**URL:** <https://discuss.elastic.co/t/how-packetbeat-determine-source-and-destination-in-tcp-flow/212313>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [December 18, 2019, 12:05pm UTC](https://discuss.elastic.co/t/how-packetbeat-determine-source-and-destination-in-tcp-flow/212313 "2019-12-18T12:05:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jaypark81](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaypark81/32/58030_2.png) [@jaypark81](https://discuss.elastic.co/u/jaypark81)\
**Post date:** [December 18, 2019, 12:05pm UTC](https://discuss.elastic.co/t/how-packetbeat-determine-source-and-destination-in-tcp-flow/212313/1 "2019-12-18T12:05:14Z")

</div>

Hi,

I'm investigating network flows. And Packetbeat collect network traffic including forwarding.

I found some flow's destination is port 80 for http.  
Otherwise, some flows source port is port 80.

I'm very sure the port 80 must be destination.  
At this point, how does Packetbeat determine source and destination?

How can we solve this issue?

Thank you in advance,  
jaypark81

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 3, 2020, 3:39am UTC](https://discuss.elastic.co/t/how-packetbeat-determine-source-and-destination-in-tcp-flow/212313/2 "2020-01-03T03:39:02Z")

</div>

It uses the first packet it sees as source. So if it has missed some packets from the beginning of the connection then it can get the source/destination wrong.

---

<div class="post-metadata">

**Author:** ![jaypark81](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaypark81/32/58030_2.png) [@jaypark81](https://discuss.elastic.co/u/jaypark81)\
**Post date:** [January 3, 2020, 6:35am UTC](https://discuss.elastic.co/t/how-packetbeat-determine-source-and-destination-in-tcp-flow/212313/3 "2020-01-03T06:35:00Z")

</div>

Understood.

Then, I worried about one Packetbeat daemon monitor many network interfaces.  
( A packetbeat daemon monitors 5 network interface now.)

Is there recommendations to set up packetbeat?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 31, 2020, 6:48am UTC](https://discuss.elastic.co/t/how-packetbeat-determine-source-and-destination-in-tcp-flow/212313/4 "2020-01-31T06:48:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
