# Http.response 404

**URL:** <https://discuss.elastic.co/t/http-response-404/131322>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [May 10, 2018, 3:08pm UTC](https://discuss.elastic.co/t/http-response-404/131322 "2018-05-10T15:08:28Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![ikrot](https://avatars.discourse-cdn.com/v4/letter/i/e56c9b/32.png) [@ikrot](https://discuss.elastic.co/u/ikrot)\
**Post date:** [May 10, 2018, 3:08pm UTC](https://discuss.elastic.co/t/http-response-404/131322/1 "2018-05-10T15:08:28Z")

</div>

Hi,

Could you help me please to figure out what is going on?  
Packetbeat returns http.response 404 for existing files.  
But in the same time when I check it manually with CURL it returns 200

packetbeat version 5.6.4  
elasticsearch version 5.5.2

Thanks.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [May 11, 2018, 6:55am UTC](https://discuss.elastic.co/t/http-response-404/131322/2 "2018-05-11T06:55:09Z")

</div>

Can you please share your packetbeat config file and logs? Please also share a bit more details on what you are trying to do?

---

<div class="post-metadata">

**Author:** ![ikrot](https://avatars.discourse-cdn.com/v4/letter/i/e56c9b/32.png) [@ikrot](https://discuss.elastic.co/u/ikrot)\
**Post date:** [May 11, 2018, 8:48am UTC](https://discuss.elastic.co/t/http-response-404/131322/3 "2018-05-11T08:48:36Z")

</div>

Hi,

packetbeat.yml

#============================== Network device ================================

packetbeat.interfaces.device: any

#================================== Flows =====================================

packetbeat.flows:

timeout: 30s

period: 10s

#========================== Transaction protocols =============================

packetbeat.protocols.http:

ports: [80, 443]

#-------------------------- Elasticsearch output ------------------------------  
output.elasticsearch:

hosts: ["sm-prod-elastic-04.va2:9200", "sm-prod-elastic-05.va2:9200", "sm-prod-elastic-06.va2:9200"]

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [May 11, 2018, 9:23am UTC](https://discuss.elastic.co/t/http-response-404/131322/4 "2018-05-11T09:23:03Z")

</div>

Please also add the logs and a bit more details on what you are trying to do. Please also try to format the above config and logs properly to make them readable.

---

<div class="post-metadata">

**Author:** ![ikrot](https://avatars.discourse-cdn.com/v4/letter/i/e56c9b/32.png) [@ikrot](https://discuss.elastic.co/u/ikrot)\
**Post date:** [May 11, 2018, 10:01am UTC](https://discuss.elastic.co/t/http-response-404/131322/5 "2018-05-11T10:01:55Z")

</div>

the log file is full of \>\>\>\>\>  
2018-05-11T08:34:12Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=54 libbeat.es.call\_count.PublishEvents=105 libbeat.es.publish.read\_bytes=51029 libbeat.es.publish.write\_byte  
s=3167012 libbeat.es.published\_and\_acked\_events=4537 libbeat.publisher.messages\_in\_worker\_queues=2073 libbeat.publisher.published\_events=4520 tcp.dropped\_because\_of\_gaps=231  
2018-05-11T08:34:42Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=40 libbeat.es.call\_count.PublishEvents=98 libbeat.es.publish.read\_bytes=46918 libbeat.es.publish.write\_bytes  
=2839994 libbeat.es.published\_and\_acked\_events=4097 libbeat.publisher.messages\_in\_worker\_queues=1719 libbeat.publisher.published\_events=4119 tcp.dropped\_because\_of\_gaps=185  
2018-05-11T08:35:12Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=32 libbeat.es.call\_count.PublishEvents=89 libbeat.es.publish.read\_bytes=42447 libbeat.es.publish.write\_bytes  
=2717090 libbeat.es.published\_and\_acked\_events=3784 libbeat.publisher.messages\_in\_worker\_queues=1884 libbeat.publisher.published\_events=3782 tcp.dropped\_because\_of\_gaps=77  
2018-05-11T08:35:42Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=39 libbeat.es.call\_count.PublishEvents=86 libbeat.es.publish.read\_bytes=41395 libbeat.es.publish.write\_bytes  
=2506780 libbeat.es.published\_and\_acked\_events=3576 libbeat.publisher.messages\_in\_worker\_queues=1758 libbeat.publisher.published\_events=3540 tcp.dropped\_because\_of\_gaps=105  
2018-05-11T08:36:12Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=55 libbeat.es.call\_count.PublishEvents=91 libbeat.es.publish.read\_bytes=43041 libbeat.es.publish.write\_bytes  
=2661650 libbeat.es.published\_and\_acked\_events=3666 libbeat.publisher.messages\_in\_worker\_queues=2055 libbeat.publisher.published\_events=3691 tcp.dropped\_because\_of\_gaps=126  
2018-05-11T08:36:30Z INFO packet decode failed with: Invalid (too small) IP header length (0 \< 5)  
2018-05-11T08:36:42Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=67 libbeat.es.call\_count.PublishEvents=102 libbeat.es.publish.read\_bytes=48986 libbeat.es.publish.write\_byte  
s=3118782 libbeat.es.published\_and\_acked\_events=4319 libbeat.publisher.messages\_in\_worker\_queues=2121 libbeat.publisher.published\_events=4295 tcp.dropped\_because\_of\_gaps=180  
2018-05-11T08:37:12Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=31 libbeat.es.call\_count.PublishEvents=99 libbeat.es.publish.read\_bytes=47092 libbeat.es.publish.write\_bytes  
=2803159 libbeat.es.published\_and\_acked\_events=4035 libbeat.publisher.messages\_in\_worker\_queues=1799 libbeat.publisher.published\_events=4054 tcp.dropped\_because\_of\_gaps=130  
2018-05-11T08:37:42Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=35 libbeat.es.call\_count.PublishEvents=90 libbeat.es.publish.read\_bytes=43349 libbeat.es.publish.write\_bytes  
=2776744 libbeat.es.published\_and\_acked\_events=3842 libbeat.publisher.messages\_in\_worker\_queues=1986 libbeat.publisher.published\_events=3852 tcp.dropped\_because\_of\_gaps=131  
2018-05-11T08:38:12Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=30 libbeat.es.call\_count.PublishEvents=91 libbeat.es.publish.read\_bytes=43638 libbeat.es.publish.write\_bytes  
=2757774 libbeat.es.published\_and\_acked\_events=3844 libbeat.publisher.messages\_in\_worker\_queues=2043 libbeat.publisher.published\_events=3830 tcp.dropped\_because\_of\_gaps=59  
2018-05-11T08:38:42Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=44 libbeat.es.call\_count.PublishEvents=84 libbeat.es.publish.read\_bytes=40174 libbeat.es.publish.write\_bytes  
=2533535 libbeat.es.published\_and\_acked\_events=3507 libbeat.publisher.messages\_in\_worker\_queues=1869 libbeat.publisher.published\_events=3528 tcp.dropped\_because\_of\_gaps=119  
2018-05-11T08:39:12Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=27 libbeat.es.call\_count.PublishEvents=87 libbeat.es.publish.read\_bytes=40890 libbeat.es.publish.write\_bytes=2509261 libbeat.es.published\_and\_acked\_events=3418 libbeat.publisher.messages\_in\_worker\_queues=2013 libbeat.publisher.published\_events=3378 tcp.dropped\_because\_of\_gaps=23  
2018-05-11T08:39:42Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=26 libbeat.es.call\_count.PublishEvents=76 libbeat.es.publish.read\_bytes=35931 libbeat.es.publish.write\_bytes=2211417 libbeat.es.published\_and\_acked\_events=3032 libbeat.publisher.messages\_in\_worker\_queues=1720 libbeat.publisher.published\_events=3041 tcp.dropped\_because\_of\_gaps=81  
2018-05-11T08:40:12Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=26 libbeat.es.call\_count.PublishEvents=87 libbeat.es.publish.read\_bytes=41027 libbeat.es.publish.write\_bytes=2541132 libbeat.es.published\_and\_acked\_events=3444 libbeat.publisher.messages\_in\_worker\_queues=2138 libbeat.publisher.published\_events=3436 tcp.dropped\_because\_of\_gaps=37  
2018-05-11T08:40:42Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=32 libbeat.es.call\_count.PublishEvents=85 libbeat.es.publish.read\_bytes=40269 libbeat.es.publish.write\_bytes=2533687 libbeat.es.published\_and\_acked\_events=3419 libbeat.publisher.messages\_in\_worker\_queues=2100 libbeat.publisher.published\_events=3417 tcp.dropped\_because\_of\_gaps=83  
2018-05-11T08:41:12Z INFO Non-zero metrics in the last 30s: http.unmatched\_responses=29 libbeat.es.call\_count.PublishEvents=87 libbeat.es.publish.read\_bytes=41639 libbeat.es.publish.write\_bytes=2673085 libbeat.es.published\_and\_acked\_events=3631 libbeat.publisher.messages\_in\_worker\_queues=2229 libbeat.publisher.published\_events=3666 tcp.dropped\_because\_of\_gaps=60  
2018-05-11T08:41:24Z INFO packet decode failed with: Invalid (too small) IP header length (0 \< 5)

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [May 14, 2018, 9:16am UTC](https://discuss.elastic.co/t/http-response-404/131322/6 "2018-05-14T09:16:18Z")

</div>

One interesting bit in the above log:

> [@ikrot](#):
>
> 2018-05-11T08:41:24Z INFO packet decode failed with: Invalid (too small) IP header length (0 \< 5)

What we are still missing here is some more details on what you exactly try to do?

---

<div class="post-metadata">

**Author:** ![ikrot](https://avatars.discourse-cdn.com/v4/letter/i/e56c9b/32.png) [@ikrot](https://discuss.elastic.co/u/ikrot)\
**Post date:** [May 25, 2018, 10:15am UTC](https://discuss.elastic.co/t/http-response-404/131322/7 "2018-05-25T10:15:15Z")

</div>

The main case: Checking the response codes for static files.  
I use Packetbeat for sending the responses to ELK.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [May 25, 2018, 12:39pm UTC](https://discuss.elastic.co/t/http-response-404/131322/8 "2018-05-25T12:39:59Z")

</div>

Thanks for the details. So if I understand you correctly, you make a http request through curl and get a 200 response but the packet captured by packetbeat says it's a 400? Could you share the full json content of this document to see if there any other interesting bits inside that could give use more details?

---

<div class="post-metadata">

**Author:** ![ikrot](https://avatars.discourse-cdn.com/v4/letter/i/e56c9b/32.png) [@ikrot](https://discuss.elastic.co/u/ikrot)\
**Post date:** [May 25, 2018, 1:31pm UTC](https://discuss.elastic.co/t/http-response-404/131322/9 "2018-05-25T13:31:42Z")

</div>

I make a http request through curl and get:

$ curl -I [https://host/vs\_fb\_en/assets\_haxe/cid\_1525940250739/\_hx\_assets/remote/root-package-html5.json](https://host/vs_fb_en/assets_haxe/cid_1525940250739/_hx_assets/remote/root-package-html5.json)  
HTTP/2 200  
server: VSP  
content-type: application/json  
last-modified: Fri, 25 May 2018 11:49:24 GMT  
etag: "5b07f844-4ae8c"  
access-control-allow-origin: \*  
content-length: 306828  
accept-ranges: bytes  
x-varnish: 1296387168  
host: host  
cache-control: public, max-age=31535855  
expires: Sat, 25 May 2019 13:24:26 GMT  
date: Fri, 25 May 2018 13:26:51 GMT

at the same time in kibana for packetbeat index:

http.request.headers.content-length |0|  
http.request.headers.content-type |text/plain; charset=UTF-8|  
http.response.code |404|  
http.response.headers.content-length |178|  
http.response.headers.content-type |text/html|  
http.response.phrase |Found|  
ip |10.144.4.37|  
method |GET|  
path |host/vs\_fb\_en/assets\_haxe/cid\_1527253507926/\_hx\_assets/remote/root-package-html5.json| port |80|  
proc ||  
query |GET /host/vs\_fb\_en/assets\_haxe/cid\_1527253507926/\_hx\_assets/remote/root-package-html5.json|

---

<div class="post-metadata">

**Author:** ![ikrot](https://avatars.discourse-cdn.com/v4/letter/i/e56c9b/32.png) [@ikrot](https://discuss.elastic.co/u/ikrot)\
**Post date:** [May 25, 2018, 1:33pm UTC](https://discuss.elastic.co/t/http-response-404/131322/10 "2018-05-25T13:33:33Z")

</div>

$ curl -I [http://host/vs\_fb\_en/assets\_haxe/cid\_1527253507926/\_hx\_assets/remote/root-package-html5.json](http://host/vs_fb_en/assets_haxe/cid_1527253507926/_hx_assets/remote/root-package-html5.json)  
HTTP/1.1 200 OK  
Server: VSP  
Content-Type: application/json  
Last-Modified: Fri, 25 May 2018 11:49:24 GMT  
ETag: "5b07f844-4ae8c"  
Access-Control-Allow-Origin: \*  
Content-Length: 306828  
Accept-Ranges: bytes  
X-Varnish: 1296517258  
Host: host  
Cache-Control: public, max-age=31535955  
Expires: Sat, 25 May 2019 13:32:21 GMT  
Date: Fri, 25 May 2018 13:33:06 GMT  
Connection: keep-alive  
Set-Cookie: f5avrbbbbbbbbbbbbbbbb=JCBABHEGICPEKLCMPLJLFKNEFKLFLNKEPCMAGFEHKHDGOMAIHGPBINOMAMHGIONFFOHLINPAEPFDKHGJGBNLOKAEGMDAKDFCHACMLMCNEGPBCMAGEBDHPNKNKGGFFENK; HttpOnly

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [May 29, 2018, 8:41am UTC](https://discuss.elastic.co/t/http-response-404/131322/11 "2018-05-29T08:41:31Z")

</div>

Hi,

Your original request used HTTP/2, which is not supported by Packetbeat, so it was not captured.

The 404 error that you observe in Kibana is for a different path, so it was caused by another request. Is it possible that this request failed with a 404?

Please repeat the scenario by passing the `--http1.1` argument to curl, so it doesn't use http2.

---

<div class="post-metadata">

**Author:** ![ikrot](https://avatars.discourse-cdn.com/v4/letter/i/e56c9b/32.png) [@ikrot](https://discuss.elastic.co/u/ikrot)\
**Post date:** [June 6, 2018, 12:33pm UTC](https://discuss.elastic.co/t/http-response-404/131322/12 "2018-06-06T12:33:15Z")

</div>

I have got the same result for --http1.1

---

<div class="post-metadata">

**Author:** ![ikrot](https://avatars.discourse-cdn.com/v4/letter/i/e56c9b/32.png) [@ikrot](https://discuss.elastic.co/u/ikrot)\
**Post date:** [June 12, 2018, 3:35pm UTC](https://discuss.elastic.co/t/http-response-404/131322/13 "2018-06-12T15:35:21Z")

</div>

I'm just wondered if I only one with this issue)

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [June 13, 2018, 1:31am UTC](https://discuss.elastic.co/t/http-response-404/131322/14 "2018-06-13T01:31:54Z")

</div>

can you show an example of a request with --http1.1 that doesn't fail and its indexed as a 404?

---

<div class="post-metadata">

**Author:** ![ikrot](https://avatars.discourse-cdn.com/v4/letter/i/e56c9b/32.png) [@ikrot](https://discuss.elastic.co/u/ikrot)\
**Post date:** [June 13, 2018, 9:04am UTC](https://discuss.elastic.co/t/http-response-404/131322/15 "2018-06-13T09:04:50Z")

</div>

![32%20PM](https://us1.discourse-cdn.com/elastic/original/3X/3/7/37ac335892f0bb74df080a9a585088fb2a96f370.png)

 ![10%20PM](https://us1.discourse-cdn.com/elastic/original/3X/9/0/9026b66e42b2194d7f632dc7861c31ed93caa1ab.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2018, 9:04am UTC](https://discuss.elastic.co/t/http-response-404/131322/16 "2018-07-11T09:04:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
