# Packetbeat capturing responsetime and sending it to Logstash

**URL:** https://discuss.elastic.co/t/packetbeat-capturing-responsetime-and-sending-it-to-logstash/253155
**Category:** Beats
**Tags:** packetbeat
**Created:** [October 23, 2020, 3:16pm UTC](https://discuss.elastic.co/t/packetbeat-capturing-responsetime-and-sending-it-to-logstash/253155 "2020-10-23T15:16:32Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![21908](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/21908/32/77808_2.png) [@21908](https://discuss.elastic.co/u/21908)
#### Post date: [October 23, 2020, 3:16pm UTC](https://discuss.elastic.co/t/packetbeat-capturing-responsetime-and-sending-it-to-logstash/253155/1 "2020-10-23T15:16:32Z")

</div>

My goal is to capture and store all queries run against Elasticsearch in Elasticsearch. I am mimicking the scenario discussed at [monitoring-the-search-queries](https://www.elastic.co/blog/monitoring-the-search-queries). I am using v7.9.2 of Elasticsearch, Logstash, Kibana and Packetbeat software. The issue I'm having right now, is that I'm not capturing responsetime. I do not see responsetime field in the new Elasticsearch index that is created. I am guessing/suspecting, that its either because (1) Packetbeat is not configured correctly and pulling that information or (2) Logstash  
configuration file needs to be corrected. I'm posting my packetbeat.yml and logstash.conf file below, in th hopes that someone can point me in the right direction.

Logstash - sniff\_search.conf

```auto
    input {
      beats { port => 5044 }
    }
    filter {
      if "search" in [request]{
        grok { match => { "request" => ".*\n\{(?<query_body>.*)"} }
        grok { match => { "path" => "\/(?<index>.*)\/_search"} }
        if [index] { } 
        else { mutate { add_field => { "index" => "All" } } }
        mutate { update => { "query_body" => "{%{query_body}" } }
      }
    }
    output {
      if "search" in [request] and "ignore_unmapped" not in [query_body]{
        elasticsearch { hosts => "<ES MASTER NODE>:9200" }
      }
    } 

```

packetbeat.yml

```auto
    packetbeat.interfaces:
      device: any
      type: af_packet

    packetbeat.flows: 
      timeout: 30s
      period: 10s

    packetbeat.protocols:
    - type: http    
      include_body_for: ["application/json", "x-www-form-urlencoded"]  
      ports: [9200]
      send_request: true   
      
    setup.template.settings:
      index.number_of_shards: 1
      
    setup.kibana:
      host: "<KIBANA IP>:5601"

    output.logstash:  
      hosts: ["<LOGSTASH IP>:5044"]

    processors:
      - add_host_metadata: ~
      - add_cloud_metadata: ~
      - add_docker_metadata: ~

```

---

<div class="post-metadata">

### Author: ![Glen\_Meng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_meng/32/78044_2.png) [@Glen\_Meng](https://discuss.elastic.co/u/Glen_Meng)
#### Post date: [October 30, 2020, 2:56am UTC](https://discuss.elastic.co/t/packetbeat-capturing-responsetime-and-sending-it-to-logstash/253155/2 "2020-10-30T02:56:55Z")

</div>

I run into the same environment, I'm using packetbeat 7.6.0 and also I can't see http responsetime in captured record

---

<div class="post-metadata">

### Author: ![21908](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/21908/32/77808_2.png) [@21908](https://discuss.elastic.co/u/21908)
#### Post date: [November 4, 2020, 8:50pm UTC](https://discuss.elastic.co/t/packetbeat-capturing-responsetime-and-sending-it-to-logstash/253155/3 "2020-11-04T20:50:00Z")

</div>

I'm still interested in someone who can provide some detail/reasoning on this issue.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 2, 2020, 10:50pm UTC](https://discuss.elastic.co/t/packetbeat-capturing-responsetime-and-sending-it-to-logstash/253155/4 "2020-12-02T22:50:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
