# Packetbeat - Bug parsing http method

**URL:** <https://discuss.elastic.co/t/packetbeat-bug-parsing-http-method/250095>\
**Category:** Beats\
**Tags:** beats-development, packetbeat\
**Created:** [September 27, 2020, 4:29pm UTC](https://discuss.elastic.co/t/packetbeat-bug-parsing-http-method/250095 "2020-09-27T16:29:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ebanashka](https://avatars.discourse-cdn.com/v4/letter/e/c89c15/32.png) [@ebanashka](https://discuss.elastic.co/u/ebanashka)\
**Post date:** [September 27, 2020, 4:29pm UTC](https://discuss.elastic.co/t/packetbeat-bug-parsing-http-method/250095/1 "2020-09-27T16:29:46Z")

</div>

Hi,

I've stumbled upon a weird bug with http protocol method parsing. Upon feeding the following PCAP file [https://drive.google.com/file/d/11DN4ZXbWE-W83VdwSRfJA04jBbOLMzs3/view?usp=sharing](https://drive.google.com/file/d/11DN4ZXbWE-W83VdwSRfJA04jBbOLMzs3/view?usp=sharing) to the latest packetbeat one of the requests ends up having method looking like this: `l_id\":\"f550e6c4-9303-4b70-a640-5c0e1d2fc0d3\"}}`. The capture looks just fine in Wireshark. I've obtained the file by capturing http traffic on port 9200 with the following basic setup: [https://gist.github.com/dmsergeev/add4770be0475e4bc2ea9ec4b37b4edf](https://gist.github.com/dmsergeev/add4770be0475e4bc2ea9ec4b37b4edf)

I tried looking at the code and it seems like that the problem is somewhere in the TCP layer code as parsing works as intended establishing that the `Request-Line` of the request is: `l_id\":\"f550e6c4-9303-4b70-a640-5c0e1d2fc0d3\"}}\nPOST /_bulk HTTP/1.1` which is as far as I can see does not violate the http specification.

You can easily generate your own PCAP file like this by following the following steps:

1. Copy both `docker-compose.yml` and `packetbeat.yml` on your machine
2. Run `docker-compose up`
3. Run `sudo tcpdump -i any -s 1514 'tcp port 9200' -w path_to_pcap.pcap`. I've chosen snaplen to be 1514 to match packetbeat config
4. Feed that to packetbeat

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2020, 6:29pm UTC](https://discuss.elastic.co/t/packetbeat-bug-parsing-http-method/250095/2 "2020-10-25T18:29:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
