# How to Use Machine Learning with Packetbeat to Detect Network Anomalies in Elastic Stack?

**URL:** <https://discuss.elastic.co/t/how-to-use-machine-learning-with-packetbeat-to-detect-network-anomalies-in-elastic-stack/378075>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [May 13, 2025, 9:31am UTC](https://discuss.elastic.co/t/how-to-use-machine-learning-with-packetbeat-to-detect-network-anomalies-in-elastic-stack/378075 "2025-05-13T09:31:07Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![nzeland149](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nzeland149/32/143060_2.png) [@nzeland149](https://discuss.elastic.co/u/nzeland149)\
**Post date:** [May 13, 2025, 9:31am UTC](https://discuss.elastic.co/t/how-to-use-machine-learning-with-packetbeat-to-detect-network-anomalies-in-elastic-stack/378075/1 "2025-05-13T09:31:07Z")

</div>

I'm currently working on a network monitoring project using the **Elastic Stack** and **Packetbeat** , and I'm interested in using **Elastic Machine Learning** to **detect anomalies in network traffic**. However, I'm not sure how to properly set up a machine learning job for this use case.

- **Packetbeat** is installed and running on a server, successfully shipping network flow and protocol data to **Elasticsearch**.
- I can see Packetbeat data in **Kibana** , including flows, source/destination IPs, ports, etc.
- I'm using **Elastic Stack 7.17.13**.  
 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/4/7/474c6f5b79954eea81749ca4b92f034693aeb56f.png)
