we sitting here in a Study-Project in Germany and want to work with packetbeat and ELK to find security issues in network-traffic. The live-capturing works fine.
Now, we want to import our old PCAP-files from the last 3 years (approx. 3GB/day). If we use
"packetbeat run -I "PCAP-FILE" -t "
we see captured packets in Kibana, but only 700 packets per 30 minutes. There should be much more! It seems that packetbeat stops after this 700 packets.
Can somebody help us to solve this problem?
The only logs we see in Kibana are ICMP-Packets
If we use live-capturing, we see all the traffic. We use the same config-file.