# Monitor particular port using elk

**URL:** <https://discuss.elastic.co/t/monitor-particular-port-using-elk/141575>\
**Category:** Beats\
**Created:** [July 25, 2018, 1:02pm UTC](https://discuss.elastic.co/t/monitor-particular-port-using-elk/141575 "2018-07-25T13:02:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dinesh1](https://avatars.discourse-cdn.com/v4/letter/d/7bcc69/32.png) [@dinesh1](https://discuss.elastic.co/u/dinesh1)\
**Post date:** [July 25, 2018, 1:03pm UTC](https://discuss.elastic.co/t/monitor-particular-port-using-elk/141575/1 "2018-07-25T13:03:00Z")

</div>

how monitor number of active connections in particular port.Like 22, 9090, 15672 etc using elk

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [July 26, 2018, 1:02pm UTC](https://discuss.elastic.co/t/monitor-particular-port-using-elk/141575/2 "2018-07-26T13:02:27Z")

</div>

Hello @dinesh1, You can do that with metricbeat and the [System socket metricset](https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-metricset-system-socket.html), this will catch all the TCP connection you have on the machine and you can filter them by ports in kibana.

---

<div class="post-metadata">

**Author:** ![dinesh1](https://avatars.discourse-cdn.com/v4/letter/d/7bcc69/32.png) [@dinesh1](https://discuss.elastic.co/u/dinesh1)\
**Post date:** [July 26, 2018, 1:04pm UTC](https://discuss.elastic.co/t/monitor-particular-port-using-elk/141575/3 "2018-07-26T13:04:00Z")

</div>

can i get how many active connection on particular port

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [July 26, 2018, 1:16pm UTC](https://discuss.elastic.co/t/monitor-particular-port-using-elk/141575/4 "2018-07-26T13:16:41Z")

</div>

The way the metricset works is it will periodically poll the kernel to ask to retrieve the number of TCP Socket connection. It will create a new document per connection, so you can filter by port and create a graph in kibana that will show the number of connection over time.

When a connection is dropped the next poll won't detect it, so you will only have the active TCP connection.

The result of the socket metricset is similar to a 'lsof' output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2018, 3:16pm UTC](https://discuss.elastic.co/t/monitor-particular-port-using-elk/141575/5 "2018-08-23T15:16:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
