# Monitor uncommon ports

**URL:** <https://discuss.elastic.co/t/monitor-uncommon-ports/144231>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [August 13, 2018, 7:53pm UTC](https://discuss.elastic.co/t/monitor-uncommon-ports/144231 "2018-08-13T19:53:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pclaudiowsi](https://avatars.discourse-cdn.com/v4/letter/p/df705f/32.png) [@pclaudiowsi](https://discuss.elastic.co/u/pclaudiowsi)\
**Post date:** [August 13, 2018, 7:53pm UTC](https://discuss.elastic.co/t/monitor-uncommon-ports/144231/1 "2018-08-13T19:53:08Z")

</div>

Hi, I'm trying to configure packet beat on a linux server that is trying to remotely access the Microsoft's Windows Management Instrumentation (wmi). How can I configure the packetbeat.protocols section to monitor ports 135 and 139?

Thanks!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 13, 2018, 8:17pm UTC](https://discuss.elastic.co/t/monitor-uncommon-ports/144231/2 "2018-08-13T20:17:37Z")

</div>

Packetbeat supports decoding a specific set of protocols. They are listed [here](https://www.elastic.co/guide/en/beats/packetbeat/current/configuration-protocols.html). Unless WMI is operating over HTTP or TLS then Packetbeat won't be able to tell you much about the application layer.

But Packetbeat can still tell you general information about the flows. You can see an example of this in the [documentation for flows](https://www.elastic.co/guide/en/beats/packetbeat/current/configuration-flows.html). By default it will monitor all traffic. You may be interested in monitoring a subset of the traffic and you can do this by setting up a custom [BPF filter](https://www.elastic.co/guide/en/beats/packetbeat/6.3/configuration-interfaces.html#_literal_bpf_filter_literal).

```auto
packetbeat.interfaces.device: eth0
packetbeat.interfaces.type: af_packet
packetbeat.interfaces.buffer_size_mb: 100
packetbeat.interfaces.snaplen: 1514
packetbeat.interfaces.bpf_filter: "port 135 or port 139"

packetbeat.flows:
  enabled: true
  timeout: 30s
  period: 1m

output.elasticsearch.hosts: ['http://localhost:9200']

```

---

<div class="post-metadata">

**Author:** ![pclaudiowsi](https://avatars.discourse-cdn.com/v4/letter/p/df705f/32.png) [@pclaudiowsi](https://discuss.elastic.co/u/pclaudiowsi)\
**Post date:** [August 13, 2018, 10:45pm UTC](https://discuss.elastic.co/t/monitor-uncommon-ports/144231/3 "2018-08-13T22:45:22Z")

</div>

I was able to setup packetbeat to trace the network flow with the config you provided.

Thanks for the help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2018, 10:48pm UTC](https://discuss.elastic.co/t/monitor-uncommon-ports/144231/4 "2018-09-10T22:48:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
