# Packetbeat agent not returning HTTP fields

**URL:** <https://discuss.elastic.co/t/packetbeat-agent-not-returning-http-fields/97277>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [August 16, 2017, 2:25pm UTC](https://discuss.elastic.co/t/packetbeat-agent-not-returning-http-fields/97277 "2017-08-16T14:25:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Post date:** [August 16, 2017, 2:25pm UTC](https://discuss.elastic.co/t/packetbeat-agent-not-returning-http-fields/97277/1 "2017-08-16T14:25:08Z")

</div>

Packetbeat 1.2.2  
ElasticSearch 2.1.0  
OS: Windows Server 2008 R2

I have deployed packetbeat agent on a Windows system. It is returning following fields.

beat.hostname  
client\_ip  
client\_port  
direction  
ip  
method  
port  
query  
resource  
type  
@timestamp  
\_id  
\_index  
\_score  
\_type  
[beat.name](http://beat.name)  
bytes\_in  
bytes\_out  
client\_proc  
client\_server  
count  
dns.additionals  
dns.additionals\_count  
dns.answers  
dns.answers\_count  
dns.authorities  
dns.authorities\_count  
dns.flags.authoritative  
dns.flags.recursion\_allowed  
dns.flags.recursion\_desired  
dns.flags.truncated\_response  
[dns.id](http://dns.id)  
dns.op\_code  
dns.question.class  
[dns.question.name](http://dns.question.name)  
dns.question.type  
dns.response\_code  
notes  
proc  
responsetime  
server  
status  
transport

As we can see the http fields are missing. We are struggling with this issue. Can anybody help.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 17, 2017, 9:14pm UTC](https://discuss.elastic.co/t/packetbeat-agent-not-returning-http-fields/97277/2 "2017-08-17T21:14:27Z")

</div>

Have you checked any events with `type: http` being indexed in Elasticsearch?

Also checks packetbeat logs for potential parsing errors.

Also verify the device you configured is really the one used to send/receive HTTP requests.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2017, 9:14pm UTC](https://discuss.elastic.co/t/packetbeat-agent-not-returning-http-fields/97277/3 "2017-09-14T21:14:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
