# \[Packetbeat\] bpf\_filter setting does not work in packetbeat 8.x.

**URL:** https://discuss.elastic.co/t/packetbeat-bpf-filter-setting-does-not-work-in-packetbeat-8-x/332622
**Category:** Beats
**Tags:** packetbeat
**Created:** [May 5, 2023, 7:37am UTC](https://discuss.elastic.co/t/packetbeat-bpf-filter-setting-does-not-work-in-packetbeat-8-x/332622 "2023-05-05T07:37:08Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![md-irohas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/md-irohas/32/120630_2.png) [@md-irohas](https://discuss.elastic.co/u/md-irohas)
#### Post date: [May 5, 2023, 7:37am UTC](https://discuss.elastic.co/t/packetbeat-bpf-filter-setting-does-not-work-in-packetbeat-8-x/332622/1 "2023-05-05T07:37:08Z")

</div>

I am using packetbeat (v8.7.0) in my home network and find that the `packetbeat.interfaces.bpf_filter` setting in packetbeat.yml does not work.

I read the source code and find that the bpf\_filter value is not addressed correctly in packetbeat/sniffer/sniffer.go (even in the latest commit).

The bpf\_filter value in packetbeat.yml is loaded to an `InterfaceConfig` instance in the sniffer.go, and a `sniffer` instance uses its 'filter' attribute when executing `openPcap`/`openAFPacket` functions. However, the `InterfaceConfig.BpfFilter` value is not copied to the `sniffer.filter`, so the 'filter' value passed to the openPcap/openAFPacket functions is always an empty string and that's why the bpf\_filter setting does not work.

Maybe, just adding one line is enough to fix this bug (I've not run `make testsuite`, but the fixed packetbeat executable works in my home as I expected).

```diff
diff --git a/packetbeat/sniffer/sniffer.go b/packetbeat/sniffer/sniffer.go
index efb12d045a..73b50771b5 100644
--- a/packetbeat/sniffer/sniffer.go
+++ b/packetbeat/sniffer/sniffer.go
@@ -141,6 +141,7 @@ func New(testMode bool, _ string, decoders Decoders, interfaces []config.Interfa
                }
 
                child.config = iface
+ child.filter = iface.BpfFilter
                s.sniffers[i] = child
        }

```

Could someone fix this?

---

<div class="post-metadata">

### Author: ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)
#### Post date: [May 5, 2023, 10:59am UTC](https://discuss.elastic.co/t/packetbeat-bpf-filter-setting-does-not-work-in-packetbeat-8-x/332622/2 "2023-05-05T10:59:13Z")

</div>

Hi @md-irohas ,

Welcome to the community! Thank you so much for investigating this issue and proposing a fix. We appreciate the details and the effort taken.

We are always happy to accept contributions from the community to make our solutions better in line with our [Contribution guidelines on GitHub](https://github.com/elastic/beats/blob/master/CONTRIBUTING.md)! Would you be happy to raise an issue and PR with this fix on the [@elastic/beats](https://github.com/elastic/beats) GitHub repo?

---

<div class="post-metadata">

### Author: ![md-irohas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/md-irohas/32/120630_2.png) [@md-irohas](https://discuss.elastic.co/u/md-irohas)
#### Post date: [May 6, 2023, 2:08am UTC](https://discuss.elastic.co/t/packetbeat-bpf-filter-setting-does-not-work-in-packetbeat-8-x/332622/3 "2023-05-06T02:08:17Z")

</div>

Hi Carly,

Thank you for the reply.  
OK, I will 🙂

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 3, 2023, 4:08am UTC](https://discuss.elastic.co/t/packetbeat-bpf-filter-setting-does-not-work-in-packetbeat-8-x/332622/4 "2023-06-03T04:08:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
