# Packetbeat 7.x not working on Windows

**URL:** <https://discuss.elastic.co/t/packetbeat-7-x-not-working-on-windows/351533>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [January 22, 2024, 11:05am UTC](https://discuss.elastic.co/t/packetbeat-7-x-not-working-on-windows/351533 "2024-01-22T11:05:31Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![eagle840](https://avatars.discourse-cdn.com/v4/letter/e/d78d45/32.png) [@eagle840](https://discuss.elastic.co/u/eagle840)\
**Post date:** [January 22, 2024, 11:05am UTC](https://discuss.elastic.co/t/packetbeat-7-x-not-working-on-windows/351533/1 "2024-01-22T11:05:31Z")

</div>

Any version of packetbeat.exe version 7.x on windows returns nothing.

eg:  
user\> packetbeat -v  
user \>

The same effect is seen in powershell and cmdline, and reproduced the effect on different machines.

However removing v7.x and installing v8.x and the command works as expect.

Even running the command directly from is native folder, with a specified packetbeat.yml has the same effect - running the command returns no output.

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 22, 2024, 2:58pm UTC](https://discuss.elastic.co/t/packetbeat-7-x-not-working-on-windows/351533/2 "2024-01-22T14:58:19Z")

</div>

Hi,

Try running Packetbeat with the `-d "*"` flag to enable debug mode, which might provide more detailed output about what's happening.

```auto
packetbeat -d "*"

```

Regards

---

<div class="post-metadata">

**Author:** ![eagle840](https://avatars.discourse-cdn.com/v4/letter/e/d78d45/32.png) [@eagle840](https://discuss.elastic.co/u/eagle840)\
**Post date:** [January 22, 2024, 4:33pm UTC](https://discuss.elastic.co/t/packetbeat-7-x-not-working-on-windows/351533/3 "2024-01-22T16:33:17Z")

</div>

Thanks for the suggestion @yago82 , however it produces the same result - no output.

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [January 22, 2024, 5:20pm UTC](https://discuss.elastic.co/t/packetbeat-7-x-not-working-on-windows/351533/4 "2024-01-22T17:20:54Z")

</div>

I provisioned a `Windows Server 2022 Datacenter` system and downloaded "packetbeat-7.17.0-windows-x86\_64.zip" and "packetbeat-8.12.0-windows-x86\_64.zip". I did not modify the config. I did separately install winpcap.

I then invoked each with `packetbeat -v -d "*"`

I get the same behavior with both, no output to the command prompt but the creation of a `logs` folder next to the binary. The logs indicate that packetbeat is running successfully and listening to traffic.

Can you confirm you do not see a `logs` folder next to the binary? Is the command returning immediately and you can run other commands or do you have to control+c to exit? Did you install winpcap?

---

<div class="post-metadata">

**Author:** ![eagle840](https://avatars.discourse-cdn.com/v4/letter/e/d78d45/32.png) [@eagle840](https://discuss.elastic.co/u/eagle840)\
**Post date:** [January 22, 2024, 5:53pm UTC](https://discuss.elastic.co/t/packetbeat-7-x-not-working-on-windows/351533/5 "2024-01-22T17:53:09Z")

</div>

I have no logs folder showing. I do not have winpcap installed, but have Npcap installed, that I use with Wireshark.

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [January 22, 2024, 6:12pm UTC](https://discuss.elastic.co/t/packetbeat-7-x-not-working-on-windows/351533/6 "2024-01-22T18:12:31Z")

</div>

Can you try adding `-e` and see if you get output to your command prompt?

`packetbeat run -v --d "*" -e`

[This dumps all logs to stderr](https://www.elastic.co/guide/en/beats/packetbeat/current/command-line-options.html) which does log to console for me.

```auto
-e, --e
Logs to stderr and disables syslog/file output.

```

If that doesn't log to console for you can you also answer the following questions?

- Is the command returning immediately and you can run other commands or do you have to control+c to exit?
- What version of Windows are you running?

---

<div class="post-metadata">

**Author:** ![eagle840](https://avatars.discourse-cdn.com/v4/letter/e/d78d45/32.png) [@eagle840](https://discuss.elastic.co/u/eagle840)\
**Post date:** [January 23, 2024, 9:50am UTC](https://discuss.elastic.co/t/packetbeat-7-x-not-working-on-windows/351533/7 "2024-01-23T09:50:46Z")

</div>

Same result. After hitting enter, I am instantly presented with a new command line.

Windows version: Windows 11 Enterprise, 10.0.22621 Build 22621  
The other machine is  
Windows 11 Pro, 10.0.22621 build 22621

Both machines are always kept upto date. both have the same issue.

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [January 26, 2024, 1:58pm UTC](https://discuss.elastic.co/t/packetbeat-7-x-not-working-on-windows/351533/8 "2024-01-26T13:58:13Z")

</div>

Can you share your config?

Can you download a fresh copy of packetbeat and run it with the default config? Do you get the same behavior?

Any other details about the windows instances like Antivirus software that might be relevant?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 23, 2024, 3:58pm UTC](https://discuss.elastic.co/t/packetbeat-7-x-not-working-on-windows/351533/9 "2024-02-23T15:58:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
