# Is Network Traffic (Fleet Integration) the new Packetbeat? - Missing Netfow?

**URL:** <https://discuss.elastic.co/t/is-network-traffic-fleet-integration-the-new-packetbeat-missing-netfow/285636>\
**Category:** Elastic Observability\
**Tags:** fleet\
**Created:** [September 30, 2021, 11:08pm UTC](https://discuss.elastic.co/t/is-network-traffic-fleet-integration-the-new-packetbeat-missing-netfow/285636 "2021-09-30T23:08:04Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [September 30, 2021, 11:08pm UTC](https://discuss.elastic.co/t/is-network-traffic-fleet-integration-the-new-packetbeat-missing-netfow/285636/1 "2021-09-30T23:08:04Z")

</div>

Hi Guys,

I noticed that the integration didn't create the indices for network flow. Is this a bug or missed configuration?

 ![Screen Shot 2021-10-01 at 12.53.38 AM](https://us1.discourse-cdn.com/elastic/original/3X/8/d/8d17bcc2648886f83e72feed93ff1af85287470e.png)  
 ![Screen Shot 2021-10-01 at 1.01.20 AM](https://us1.discourse-cdn.com/elastic/original/3X/c/a/caad7b026f328ad3fad0e66e9fc660331604fe7f.png)

```auto
{"type":"security_exception","reason":"action [indices:admin/auto_create] is unauthorized for API key id [y_XFOHwBVDdS0yUQQK5L] of user [elastic/fleet-server] on indices [logs-network_traffic.flow-default-2021.09.30], this action is granted by the index privileges [auto_configure,create_index,manage,all]"}, dropping event

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 1, 2021, 3:19pm UTC](https://discuss.elastic.co/t/is-network-traffic-fleet-integration-the-new-packetbeat-missing-netfow/285636/2 "2021-10-01T15:19:05Z")

</div>

I saw a similar permissions issue in [No Elastic Security Events but Agents status is "green" - #2 by andrewkroh](https://discuss.elastic.co/t/no-elastic-security-events-but-agents-status-is-green/284731/2). With that issue, recreating the policy for that agent cleared up the problem.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 1, 2021, 3:38pm UTC](https://discuss.elastic.co/t/is-network-traffic-fleet-integration-the-new-packetbeat-missing-netfow/285636/3 "2021-10-01T15:38:00Z")

</div>

Hi @zx8086 First we are not all guys 🙂

I repeated this as well ...

Curious...Where did you pull that error log line from was?

Can you provide your elastic stack version / agent version method of install OS for elastic and where you deployed the agent to?

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [October 1, 2021, 3:44pm UTC](https://discuss.elastic.co/t/is-network-traffic-fleet-integration-the-new-packetbeat-missing-netfow/285636/4 "2021-10-01T15:44:08Z")

</div>

> Curious...Where did you pull that error log line from was?

> Can you provide your elastic stack version / agent version method of install OS for elastic and where you deployed the agent to?

7.15  
Network Traffic from Elastic-Agent Integration  
From Observability Logs affecting all host Debian (RPi4) and Darwin (Mac OSX 10.13) deployed by Debian Buster 10 node

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 1, 2021, 3:49pm UTC](https://discuss.elastic.co/t/is-network-traffic-fleet-integration-the-new-packetbeat-missing-netfow/285636/5 "2021-10-01T15:49:58Z")

</div>

Thanks

> [@zx8086](#):
>
> From Observability Logs affecting all host Debian (RPi4) and Darwin (Mac OSX 10.13) deployed by Debian Buster 10 node

Ok I guess I meant was that an Elastic Agent log, Kibana log or Elasticsearch log message, no worries we will take a look.

EDIT that is a log message from the agent... we are looking.

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [October 2, 2021, 12:11am UTC](https://discuss.elastic.co/t/is-network-traffic-fleet-integration-the-new-packetbeat-missing-netfow/285636/6 "2021-10-02T00:11:54Z")

</div>

@stephenb @andrewkroh

From index .ds-logs-network\_traffic.dns-default-2021.09.30-000001

 ![Screen Shot 2021-10-02 at 1.29.52 AM](https://us1.discourse-cdn.com/elastic/original/3X/d/7/d72d7fadcdfc2dc8907909053b3447e5966f476f.png)

Also with Network Traffic...

TLS (when Enabled)

> {"type":"mapper\_parsing\_exception","reason":"failed to parse field [tls.detailed.server\_certificate\_chain] of type [keyword] ... "caused\_by":{"type":"illegal\_state\_exception","reason":"Can't get text on a START\_OBJECT at 1:3620"}}, dropping event!

Not sure how Fleet Managed integrations have mapping issues for default ingestion / pipeline setups.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 13, 2021, 3:29pm UTC](https://discuss.elastic.co/t/is-network-traffic-fleet-integration-the-new-packetbeat-missing-netfow/285636/7 "2021-10-13T15:29:53Z")

</div>

I think I found the problem with logs-network\_traffic.flow and have opened a fix.

> <https://github.com/elastic/beats/pull/28408>
>
> \## What does this PR do?
> 
> This fixes and issue with network flows being writte…n to the wrong
> index when using the Network Packet Capture integration in Fleet.
> 
> The error was:
> 
> \`{"type:"security\_exception", "reason":"action \[indices:admin/auto\_create\] is unauthorized for API key id \[xxx\] of user \[elastic/fleet-server\] on indices \[logs-network\_traffic.flow-default-2021.10.13\] …"}\`
> 
> The cause is that flows were setting \`index\` rather than \`raw\_index\`. With
> \`index\` Beats adds the date suffix, but since this is a data stream we
> want \`raw\_index\` where the value passes through as-is.
> 
> \## Why is it important?
> 
> Fleet could not ingest network flows from Packetbeat.
> 
> \## Checklist
> 
> \- \[x\] My code follows the style guidelines of this project
> \- \[\] I have commented my code, particularly in hard-to-understand areas
> \- \[\] I have made corresponding changes to the documentation
> \- \[\] I have made corresponding change to the default configuration files
> \- \[\] I have added tests that prove my fix is effective or that my feature works
> \- \[x\] I have added an entry in \`CHANGELOG.next.asciidoc\` or \`CHANGELOG-developer.next.asciidoc\`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:32am UTC](https://discuss.elastic.co/t/is-network-traffic-fleet-integration-the-new-packetbeat-missing-netfow/285636/8 "2022-11-04T08:32:34Z")

</div>


