# Is the document of develop a new protocol up to date

**URL:** <https://discuss.elastic.co/t/is-the-document-of-develop-a-new-protocol-up-to-date/75180>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [February 15, 2017, 11:26am UTC](https://discuss.elastic.co/t/is-the-document-of-develop-a-new-protocol-up-to-date/75180 "2017-02-15T11:26:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jerome\_tan](https://avatars.discourse-cdn.com/v4/letter/j/97f17d/32.png) [@jerome\_tan](https://discuss.elastic.co/u/jerome_tan)\
**Post date:** [February 15, 2017, 11:26am UTC](https://discuss.elastic.co/t/is-the-document-of-develop-a-new-protocol-up-to-date/75180/1 "2017-02-15T11:26:59Z")

</div>

Is the document "[https://www.elastic.co/guide/en/beats/packetbeat/current/protocol-modules.html](https://www.elastic.co/guide/en/beats/packetbeat/current/protocol-modules.html)" up to date? In the document

> All protocol modules implement the TcpProtocolPlugin or the UdpProtocolPlugin (or both) from the following listing (found in beats/packetbeat/protos/protos.go).

```
// Functions to be exported by a protocol plugin
type ProtocolPlugin interface {
        // Called to initialize the Plugin
        Init(test_mode bool, results publish.Transactions) error

        // Called to return the configured ports
        GetPorts() []int
}

type TcpProtocolPlugin interface {
        ProtocolPlugin

        // Called when TCP payload data is available for parsing.
        Parse(pkt *Packet, tcptuple *common.TcpTuple,
                dir uint8, private ProtocolData) ProtocolData

        // Called when the FIN flag is seen in the TCP stream.
        ReceivedFin(tcptuple *common.TcpTuple, dir uint8,
                private ProtocolData) ProtocolData

        // Called when a packets are missing from the tcp
        // stream.
        GapInStream(tcptuple *common.TcpTuple, dir uint8, nbytes int,
                private ProtocolData) (priv ProtocolData, drop bool)

        // ConnectionTimeout returns the per stream connection timeout.
        // Return <=0 to set default tcp module transaction timeout.
        ConnectionTimeout() time.Duration
}

type UdpProtocolPlugin interface {
        ProtocolPlugin

        // ParseUdp is invoked when UDP payload data is available for parsing.
        ParseUdp(pkt *Packet)
}

```

I can't find the code in beats/packetbeat/protos/protos.go.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [February 15, 2017, 11:51am UTC](https://discuss.elastic.co/t/is-the-document-of-develop-a-new-protocol-up-to-date/75180/2 "2017-02-15T11:51:19Z")

</div>

Looks like those moved in [registry.go](https://github.com/elastic/beats/blob/master/packetbeat/protos/registry.go). Could you open a ticket so that we fix the docs, please?

The guide should be mostly up-to-date, if you find other bugs please report them. I recommend following the [master version of the docs](https://www.elastic.co/guide/en/beats/packetbeat/master/new-protocol.html) if you plan to work agains Packetbeat master.

---

<div class="post-metadata">

**Author:** ![jerome\_tan](https://avatars.discourse-cdn.com/v4/letter/j/97f17d/32.png) [@jerome\_tan](https://discuss.elastic.co/u/jerome_tan)\
**Post date:** [February 15, 2017, 12:14pm UTC](https://discuss.elastic.co/t/is-the-document-of-develop-a-new-protocol-up-to-date/75180/3 "2017-02-15T12:14:49Z")

</div>

The same, I can't find the following code from file: config/config.go

```
type Protocols struct {
        Icmp Icmp
        Dns Dns
        Http Http
        Memcache Memcache
        Mysql Mysql
        Mongodb Mongodb
        Pgsql Pgsql
        Redis Redis
        Thrift Thrift
}

```

And protos/protos.go does not contain the code:

```
// Protocol constants.
const (
        UnknownProtocol Protocol = iota
    HttpProtocol
    MysqlProtocol
    RedisProtocol
    PgsqlProtocol
    ThriftProtocol
    MongodbProtocol
    DnsProtocol
    MemcacheProtocol)

// Protocol names
var ProtocolNames = []string{
        "unknown",
        "http",
        "mysql",
        "redis",
        "pgsql",
        "thrift",
        "mongodb",
        "dns",
        "memcache",
}
```

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 16, 2017, 2:51pm UTC](https://discuss.elastic.co/t/is-the-document-of-develop-a-new-protocol-up-to-date/75180/4 "2017-02-16T14:51:47Z")

</div>

@steffens Can you check the above?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [February 16, 2017, 5:22pm UTC](https://discuss.elastic.co/t/is-the-document-of-develop-a-new-protocol-up-to-date/75180/5 "2017-02-16T17:22:52Z")

</div>

beat version? Are you using the master branch? The doc is clearly outdated and mostly fits packetbeat 1.x .

We used to have a code generator for packetbeat TCP protocols. I can't currently find it in master branch, but in 5.2 release branch: [https://github.com/elastic/beats/tree/5.2/generate/packetbeat/tcp-protocol](https://github.com/elastic/beats/tree/5.2/generate/packetbeat/tcp-protocol)

The generator contains a tutorial style readme with code for a sample server you can test with (e.g. telnet to sample server and capture traffic with packetbeat).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2017, 5:23pm UTC](https://discuss.elastic.co/t/is-the-document-of-develop-a-new-protocol-up-to-date/75180/6 "2017-03-16T17:23:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
