# Packetbeat 5.0 doesn't export http traffic or Kibana doesn't display it

**URL:** <https://discuss.elastic.co/t/packetbeat-5-0-doesnt-export-http-traffic-or-kibana-doesnt-display-it/67408>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [November 28, 2016, 10:34pm UTC](https://discuss.elastic.co/t/packetbeat-5-0-doesnt-export-http-traffic-or-kibana-doesnt-display-it/67408 "2016-11-28T22:34:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vasyl](https://avatars.discourse-cdn.com/v4/letter/v/b5a626/32.png) [@Vasyl](https://discuss.elastic.co/u/Vasyl)\
**Post date:** [November 28, 2016, 10:34pm UTC](https://discuss.elastic.co/t/packetbeat-5-0-doesnt-export-http-traffic-or-kibana-doesnt-display-it/67408/1 "2016-11-28T22:34:27Z")

</div>

Hello,

I follow the configuration guideline, but seems I am missing something. I need to display http post/request in Kibana, but only thing that I can see is dest and source ip addresses.

Any help is much appreciated.

Here is the configuration.

packetbeat.yml:  
enabled: true  
ports: [80, 8080, 8000, 5000, 8002]  
send\_all\_headers: true  
include\_body\_for: ["text/html","text/xml"]  
send\_request: true  
send\_response: true

packetbeat.template.json  
"http": {  
"properties": {  
"request": {  
"properties": {  
"body": {  
"norms": false,  
"type": "text"  
},  
"params": {  
"ignore\_above": 1024,  
"type": "keyword"  
}  
}  
},  
"response": {  
"properties": {  
"body": {  
"ignore\_above": 1024,  
"type": "keyword"  
},  
"code": {  
"ignore\_above": 1024,  
"type": "keyword"  
},  
"phrase": {  
"ignore\_above": 1024,  
"type": "keyword"  
}  
}  
}  
}  
},

packetbeat.template-es2x.json:  
"http": {  
"properties": {  
"request": {  
"properties": {  
"body": {  
"index": "analyzed",  
"norms": {  
"enabled": false  
},  
"type": "string"  
},  
"params": {  
"ignore\_above": 1024,  
"index": "not\_analyzed",  
"type": "string"  
}  
}  
},  
"response": {  
"properties": {  
"body": {  
"ignore\_above": 1024,  
"index": "not\_analyzed",  
"type": "string"  
},  
"code": {  
"ignore\_above": 1024,  
"index": "not\_analyzed",  
"type": "string"  
},  
"phrase": {  
"ignore\_above": 1024,  
"index": "not\_analyzed",  
"type": "string"  
}  
}  
}  
}  
},

---

<div class="post-metadata">

**Author:** ![Vasyl](https://avatars.discourse-cdn.com/v4/letter/v/b5a626/32.png) [@Vasyl](https://discuss.elastic.co/u/Vasyl)\
**Post date:** [December 1, 2016, 8:40pm UTC](https://discuss.elastic.co/t/packetbeat-5-0-doesnt-export-http-traffic-or-kibana-doesnt-display-it/67408/2 "2016-12-01T20:40:13Z")

</div>

It seems that the problem solved after running packetbeat/scripts/import\_dashboards

After that script .kibana index has packetbeat index. Which is weird why would Kibana index would need index-pattern from packetbeat to show http packets in Kibana.

```
    "_index": ".kibana",
    "_type": "index-pattern",
    "_id": "packetbeat-*",
    "_score": 1,
    "_source": {
      "title": "packetbeat-*",
      "timeFieldName": "@timestamp",
      "fields":
```

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [December 2, 2016, 1:14pm UTC](https://discuss.elastic.co/t/packetbeat-5-0-doesnt-export-http-traffic-or-kibana-doesnt-display-it/67408/3 "2016-12-02T13:14:12Z")

</div>

You need the index pattern definition in Kibana simply to be able to select the right index. Perhaps you were looking in another index?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2016, 1:14pm UTC](https://discuss.elastic.co/t/packetbeat-5-0-doesnt-export-http-traffic-or-kibana-doesnt-display-it/67408/4 "2016-12-30T13:14:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
