We have a requirement to create and store pcap files for all of our web server traffic. I wanted to find out if anyone has used packetbeat to create pcap files to be store and also ingest the data to be used in dashboards. Also if you have any concerns or gotchas
Packetbeat will capture a certain type of packets and send them directly to ES
If you want to capture full traffic in pcap and send them to ES, think about wireshark
Check this post
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.