# Packetbeat and Kibana

**URL:** <https://discuss.elastic.co/t/packetbeat-and-kibana/128221>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [April 16, 2018, 3:14pm UTC](https://discuss.elastic.co/t/packetbeat-and-kibana/128221 "2018-04-16T15:14:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![learnnovice](https://avatars.discourse-cdn.com/v4/letter/l/f1d935/32.png) [@learnnovice](https://discuss.elastic.co/u/learnnovice)\
**Post date:** [April 16, 2018, 3:14pm UTC](https://discuss.elastic.co/t/packetbeat-and-kibana/128221/1 "2018-04-16T15:14:05Z")

</div>

Hi all  
After spending few days trying to get logstash working for  
codec =\> netflow {  
versions =\> [5,9,10]  
}

I gave up because although tcpdump was able to see the flow data being received. Logstash was listening but not capturing/writing. I came across packetbeat and decided to use that.  
I have followed packetbeat official documentation but still unable to get it working. It has been overwhelming hence I want to start fresh on the newly build server for testing with minimal setup.  
Can someone please advise if

- As the documentation suggest at [https://www.elastic.co/guide/en/beats/packetbeat/current/load-kibana-dashboards.html](https://www.elastic.co/guide/en/beats/packetbeat/current/load-kibana-dashboards.html)  
Am I ok just to have only packetbeat and Kibana installed and view the live tcpdump data from an ethernet interface. Or Elasticsearch and Logstash are also required?
- I want to view the output using Kibana API webpage from the server capturing tcpdump which is accessible via an ip address only (not able to console). Which configuration directive needs changing with the ip address of the server in config file of packetbeat or Kibana?
- post a minimal sample config for basic setup

Current server is running CentOS Linux 7 (Core) with the following  
elasticsearch.noarch 6.2.3-1 installed

filebeat.x86\_64 6.2.3-1 @logstash-6.x  
logstash.noarch 1:6.2.3-1 @logstash-6.x  
packetbeat.x86\_64 6.2.3-1 @logstash-6.x

kibana.x86\_64 6.2.3-1 installed

---

<div class="post-metadata">

**Author:** ![JKhondhu](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@JKhondhu](https://discuss.elastic.co/u/JKhondhu)\
**Post date:** [April 18, 2018, 12:17pm UTC](https://discuss.elastic.co/t/packetbeat-and-kibana/128221/2 "2018-04-18T12:17:39Z")

</div>

Hi,

You need to have Elasticsearch installed and running.

You can have packetbeat ship to Elasticsearch for then Kibana to be able to visualise and search that data.

[https://www.elastic.co/guide/en/beats/packetbeat/current/packetbeat-getting-started.html](https://www.elastic.co/guide/en/beats/packetbeat/current/packetbeat-getting-started.html)  
[https://www.elastic.co/guide/en/beats/packetbeat/current/configuring-howto-packetbeat.html](https://www.elastic.co/guide/en/beats/packetbeat/current/configuring-howto-packetbeat.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 16, 2018, 12:17pm UTC](https://discuss.elastic.co/t/packetbeat-and-kibana/128221/3 "2018-05-16T12:17:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
