# Netflows not showing protocol types in Dashboards

**URL:** <https://discuss.elastic.co/t/netflows-not-showing-protocol-types-in-dashboards/182288>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [May 22, 2019, 4:41pm UTC](https://discuss.elastic.co/t/netflows-not-showing-protocol-types-in-dashboards/182288 "2019-05-22T16:41:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ksarpong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ksarpong/32/101801_2.png) [@ksarpong](https://discuss.elastic.co/u/ksarpong)\
**Post date:** [May 22, 2019, 4:41pm UTC](https://discuss.elastic.co/t/netflows-not-showing-protocol-types-in-dashboards/182288/1 "2019-05-22T16:41:32Z")

</div>

Newbie here.. I am curious as to why my netflows are only giving the traffic but not the protocol type in the dashboards. Also are you really able to inspect packets from a cloud implementation?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [May 23, 2019, 7:29pm UTC](https://discuss.elastic.co/t/netflows-not-showing-protocol-types-in-dashboards/182288/2 "2019-05-23T19:29:40Z")

</div>

Can you give me a bit more details about the configuration you are running?

---

<div class="post-metadata">

**Author:** ![ksarpong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ksarpong/32/101801_2.png) [@ksarpong](https://discuss.elastic.co/u/ksarpong)\
**Post date:** [May 24, 2019, 1:26pm UTC](https://discuss.elastic.co/t/netflows-not-showing-protocol-types-in-dashboards/182288/3 "2019-05-24T13:26:24Z")

</div>

#============================== Network device ================================  
packetbeat.interfaces.device: any

#================================== Flows ===========================  
packetbeat.flows:

timeout: 30s

period: 10s

\*\* Under Transaction protocols I left everything as default.  
\*\*Using packetbeat 7.0.1

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 24, 2019, 9:47pm UTC](https://discuss.elastic.co/t/netflows-not-showing-protocol-types-in-dashboards/182288/4 "2019-05-24T21:47:07Z")

</div>

Packetbeat's flow monitor doesn't go much deeper than the transport layer so it will identify tcp/udp/icmp but it won't go into identifying the traffic as HTTP, for example. There are separate events that contain protocol analysis for the [supported protocols](https://www.elastic.co/guide/en/beats/packetbeat/current/packetbeat-overview.html).

> [@ksarpong](#):
>
> Also are you really able to inspect packets from a cloud implementation?

What do you mean by "cloud implementation"? What are you trying to monitor? Packetbeat captures data via libpcap or af\_packet so it can observe the traffic that's on a host's network interface.

---

<div class="post-metadata">

**Author:** ![ksarpong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ksarpong/32/101801_2.png) [@ksarpong](https://discuss.elastic.co/u/ksarpong)\
**Post date:** [May 28, 2019, 12:37pm UTC](https://discuss.elastic.co/t/netflows-not-showing-protocol-types-in-dashboards/182288/5 "2019-05-28T12:37:43Z")

</div>

In addition to observing traffic on an instance's network interface, can it observe traffic on the actual subnet ..( Honestly I think your previous answer suffices) . You answered my question, basically packetbeat isn't a substitute for a deep packet analysis as it won't go beyond the transport layer.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 28, 2019, 1:48pm UTC](https://discuss.elastic.co/t/netflows-not-showing-protocol-types-in-dashboards/182288/6 "2019-05-28T13:48:03Z")

</div>

> [@ksarpong](#):
>
> In addition to observing traffic on an instance's network interface, can it observe traffic on the actual subnet

Yes, it will report all traffic that it sees on the interfaces that it is monitoring. So when the interface is is put into promiscuous mode it _can_ capture traffic from the subnet (but generally hosts on a network only see traffic destined for that host unless you do something special like port mirroring).

For the protocols that Packetbeat understands it will do "deep inspection". Like for HTTP, DNS, or TLS it will give very detailed information.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2019, 1:48pm UTC](https://discuss.elastic.co/t/netflows-not-showing-protocol-types-in-dashboards/182288/7 "2019-06-25T13:48:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
