# 'ignore\_outgoing' doesn't work for me

**URL:** <https://discuss.elastic.co/t/ignore-outgoing-doesnt-work-for-me/37201>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [December 15, 2015, 7:27am UTC](https://discuss.elastic.co/t/ignore-outgoing-doesnt-work-for-me/37201 "2015-12-15T07:27:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![desert\_rose](https://avatars.discourse-cdn.com/v4/letter/d/8c91f0/32.png) [@desert\_rose](https://discuss.elastic.co/u/desert_rose)\
**Post date:** [December 15, 2015, 7:27am UTC](https://discuss.elastic.co/t/ignore-outgoing-doesnt-work-for-me/37201/1 "2015-12-15T07:27:40Z")

</div>

I've uncommented "#ignore\_outgoing: true" line in packetbeat.yml and restarted packetbeat, but I can still see new transactions created by the server where packetbeat installed.

Here are some fields of a transaction:  
[beat.name](http://beat.name): [mydomain.com](http://mydomain.com)  
client\_ip: 192.168.2.33  
direction: out  
ip: 192.168.2.44

[mydomain.com](http://mydomain.com) and 192.168.2.33 are the same machine, where packetbeat installed.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 16, 2015, 4:15pm UTC](https://discuss.elastic.co/t/ignore-outgoing-doesnt-work-for-me/37201/2 "2015-12-16T16:15:09Z")

</div>

where is the client installed? The option ignore\_outgoing is supposed to be used with the application server. That is the server its name (event field 'server') and the publisher name (field '[beat.name](http://beat.name)') are compared.

---

<div class="post-metadata">

**Author:** ![desert\_rose](https://avatars.discourse-cdn.com/v4/letter/d/8c91f0/32.png) [@desert\_rose](https://discuss.elastic.co/u/desert_rose)\
**Post date:** [December 17, 2015, 7:16am UTC](https://discuss.elastic.co/t/ignore-outgoing-doesnt-work-for-me/37201/3 "2015-12-17T07:16:13Z")

</div>

Thanks, steffens.

the 'server' filelds were all empty.  
The above event was a request from '192.168.2.33' to '192.168.2.44', which should have been ignored, since packetbeat was installed on '192.168.2.33' and 'ignore\_outgoing' is 'true'.  
All events' 'direction' fields should be 'out', since I set 'ignore\_outgoing:true' for all packetbeat instances, am I right?  
Now I have to figure out why 'server' is empty, any suggestions?

---

<div class="post-metadata">

**Author:** ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)\
**Post date:** [December 17, 2015, 7:57pm UTC](https://discuss.elastic.co/t/ignore-outgoing-doesnt-work-for-me/37201/4 "2015-12-17T19:57:26Z")

</div>

We are building a network topology map with all the Packetbeat instances. This information is stored in Elasticsearch and maps the IP and port of each Packetbeat instance to the name defined under `shipper->name`.

For each transaction, Packetbeat queries Elasticsearch to see if the network topology map includes the IP and port of the source and destination servers. If this information is available, the `client_server` field in the output is set to the name of the Packetbeat running on the source server, and the `server` field is set to the name of the Packetbeat running on the destination server.

By default topology map feature is disabled, so the `client_server` and `server` fields are empty.  
Because `server` is empty, then `ignore_outgoing` doesn't work as it compares the name of the `server` field with the local Packetbeat name.  
Thank you for noticing it. I will fix it right away.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:57pm UTC](https://discuss.elastic.co/t/ignore-outgoing-doesnt-work-for-me/37201/5 "2017-07-05T21:57:26Z")

</div>


