# Network Topology using Graph

**URL:** <https://discuss.elastic.co/t/network-topology-using-graph/220965>\
**Category:** Kibana\
**Created:** [February 26, 2020, 7:46am UTC](https://discuss.elastic.co/t/network-topology-using-graph/220965 "2020-02-26T07:46:46Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![l4m4l](https://avatars.discourse-cdn.com/v4/letter/l/d9b06d/32.png) [@l4m4l](https://discuss.elastic.co/u/l4m4l)\
**Post date:** [February 26, 2020, 7:46am UTC](https://discuss.elastic.co/t/network-topology-using-graph/220965/1 "2020-02-26T07:46:46Z")

</div>

Hello all,

I have indices that contain .pcap data (imported using tshark and elasticsearch BULK API). I would like to visualise this packet capture as a network topology using graph.

I am envisaging that this would go something along these lines:

- Vertices = all the host\_names (or ip\_src) in a given capture duration
- Connections = the sum of traffic from one host to another

Unfortunately it seems a bit trickier to do this than I first imagined. As in each packet there is only "ip\_src" and "ip\_dst" information, it is hard to display a group of "Vertices" by their "ip\_src" tags but then link them based on the "ip\_dst"==each Vertice.

I have managed to get as far as creating a double-up of information, by listing both the source and destination IP's as Vertices and then connecting them from there... but this isn't quite what I want as it "splits" the information (one group may have all of the traffic from "Host\_A" to other hosts, which is then repeated for each host with "Host\_A" being the receiver of network traffic).

Has anyone had a similar problem and would be able to point me towards the right path? I would appreciate any help. Thanks

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [February 26, 2020, 8:36am UTC](https://discuss.elastic.co/t/network-topology-using-graph/220965/2 "2020-02-26T08:36:51Z")

</div>

Hi @l4m4l,

a common way around this is to ingest both source and destination ip into a third field `ip` and then using this field to create the Graph instead of your two splitted fields. This is called a "role-free" field. You can do this on ingestion time by using `copy_to` in your mapping: [https://www.elastic.co/guide/en/elasticsearch/reference/current/copy-to.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/copy-to.html)

---

<div class="post-metadata">

**Author:** ![l4m4l](https://avatars.discourse-cdn.com/v4/letter/l/d9b06d/32.png) [@l4m4l](https://discuss.elastic.co/u/l4m4l)\
**Post date:** [February 26, 2020, 10:13pm UTC](https://discuss.elastic.co/t/network-topology-using-graph/220965/3 "2020-02-26T22:13:23Z")

</div>

Hi @flash1293,

Thank-you very much, this appears to be the answer that I'm looking for! Turns out tshark already outputs this field under the name "layers.ip.ip\_ip\_addr" (which contains ip\_src, ip\_dst).

By graphing the "top terms" however, this seems to disregard two packets (out of a total of 43) between two of my hosts. I know that it still registers 43 in total, because I can see that in the total when I select the "link summary". Is there a way to increase the resolution of the links, so that they will be visible even if there is only 1 document?

Thanks

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [February 27, 2020, 9:11am UTC](https://discuss.elastic.co/t/network-topology-using-graph/220965/4 "2020-02-27T09:11:41Z")

</div>

You can set the "Certainty" setting to `1` by clicking the "Settings" button in the top menu:

 ![Screenshot 2020-02-27 at 10.09.52](https://us1.discourse-cdn.com/elastic/original/3X/5/7/57fbe92c257385892e942a388a71bcbcfd8074d3.png)

To make sure all connections are shown, select all nodes and click the "link" button a few times - this should fill in missing connections if there are some:  
 ![Screenshot 2020-02-27 at 10.10.55](https://us1.discourse-cdn.com/elastic/original/3X/1/6/1659ee2eeb92d3933b2e9c205b41b4b5a705566c.png)

---

<div class="post-metadata">

**Author:** ![l4m4l](https://avatars.discourse-cdn.com/v4/letter/l/d9b06d/32.png) [@l4m4l](https://discuss.elastic.co/u/l4m4l)\
**Post date:** [March 1, 2020, 9:40pm UTC](https://discuss.elastic.co/t/network-topology-using-graph/220965/5 "2020-03-01T21:40:23Z")

</div>

Hi @flash1293, thanks - I was changing the certainty but was missing the "link" button step.

Thanks very much for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2020, 9:40pm UTC](https://discuss.elastic.co/t/network-topology-using-graph/220965/6 "2020-03-29T21:40:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
