# Packetbeat Exiting: Sniffer main loop failed: Unsupported link type: UnknownLinkType(12)

**URL:** <https://discuss.elastic.co/t/packetbeat-exiting-sniffer-main-loop-failed-unsupported-link-type-unknownlinktype-12/155370>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [November 5, 2018, 9:01am UTC](https://discuss.elastic.co/t/packetbeat-exiting-sniffer-main-loop-failed-unsupported-link-type-unknownlinktype-12/155370 "2018-11-05T09:01:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![beat2beat](https://avatars.discourse-cdn.com/v4/letter/b/45deac/32.png) [@beat2beat](https://discuss.elastic.co/u/beat2beat)\
**Post date:** [November 5, 2018, 9:01am UTC](https://discuss.elastic.co/t/packetbeat-exiting-sniffer-main-loop-failed-unsupported-link-type-unknownlinktype-12/155370/1 "2018-11-05T09:01:24Z")

</div>

Hello,

I came into this exception when trying to read a valid pcap file. I can read the file with tcpdump -r .  
I verified that this is a valid pcap file (d4 c3 b2 a1 header), but still getting this exception. I noticed that the linktype mentioned by tcpdump is linktypeRaw and I guess packetbeat can't read this link type. Is there any workaround for this situation?.

Thanks.

Edit: New problem: The peoblem was that L2 traffic was missing in the pcap file. we have been edit the packets and created new file, and now packetbeat does read the file, but it **omits** L7 of the packet (it doesn't send any SSL values to elasticsearch, only L4 and below).

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [November 8, 2018, 11:34am UTC](https://discuss.elastic.co/t/packetbeat-exiting-sniffer-main-loop-failed-unsupported-link-type-unknownlinktype-12/155370/2 "2018-11-08T11:34:09Z")

</div>

> it **omits** L7 of the packet (it doesn't send any SSL values to elasticsearch, only L4 and below).

This is probably due to a known issue with PCAP files (first point [in this issue](https://github.com/elastic/beats/issues/8255)).

If you're passing the `-t` option to Packetbeat, try without it.

---

<div class="post-metadata">

**Author:** ![beat2beat](https://avatars.discourse-cdn.com/v4/letter/b/45deac/32.png) [@beat2beat](https://discuss.elastic.co/u/beat2beat)\
**Post date:** [November 8, 2018, 11:43am UTC](https://discuss.elastic.co/t/packetbeat-exiting-sniffer-main-loop-failed-unsupported-link-type-unknownlinktype-12/155370/3 "2018-11-08T11:43:50Z")

</div>

I'm not using -t flag, just -I, for example:  
packetbeat -I pcap.pcap.

Do you have any ideas how to work with packetbeat with snort/nfqeue packets?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 6, 2018, 11:43am UTC](https://discuss.elastic.co/t/packetbeat-exiting-sniffer-main-loop-failed-unsupported-link-type-unknownlinktype-12/155370/4 "2018-12-06T11:43:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
