# PacketBeat fails to extract HTTP from simple PCAP

**URL:** <https://discuss.elastic.co/t/packetbeat-fails-to-extract-http-from-simple-pcap/103868>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [October 13, 2017, 9:51am UTC](https://discuss.elastic.co/t/packetbeat-fails-to-extract-http-from-simple-pcap/103868 "2017-10-13T09:51:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![theetete](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theetete/32/28298_2.png) [@theetete](https://discuss.elastic.co/u/theetete)\
**Post date:** [October 13, 2017, 9:51am UTC](https://discuss.elastic.co/t/packetbeat-fails-to-extract-http-from-simple-pcap/103868/1 "2017-10-13T09:51:17Z")

</div>

Hi,  
I got trouble in extracting HTTP from my tcpdumped file  
All I get is one tcp stream, but if I check with Wireshark I got full HTTP streams.

```
2017-10-13T09:40:52Z INFO packetbeat start running.
2017-10-13T09:40:52Z DBG start flows worker
2017-10-13T09:40:52Z DBG Waiting for the sniffer to finish
2017-10-13T09:40:52Z DBG Packet number: 1
2017-10-13T09:40:52Z DBG decode packet data
2017-10-13T09:40:52Z DBG lock flows
2017-10-13T09:40:52Z DBG flowid: add eth
2017-10-13T09:40:52Z DBG worker wait start(2017-10-13 09:41:00 +0000 UTC): 7.639828107s
2017-10-13T09:40:52Z DBG IPv4 packet
2017-10-13T09:40:52Z DBG flowid: add ipv4
2017-10-13T09:40:52Z DBG TCP packet
2017-10-13T09:40:52Z DBG flowid: add tcp
2017-10-13T09:40:52Z DBG flow id flags: 1041
2017-10-13T09:40:52Z DBG get flow
2017-10-13T09:40:52Z DBG lookup flow: {1041 0 255 255 255 12 255 255 255 255 255 20 255 1 0 1} => [144 177 28 86 238 13 248 202 184 68 225 84 10 1 1 115 10 1 5 37 80 0 128 99]
2017-10-13T09:40:52Z DBG create new flow
2017-10-13T09:40:52Z DBG unlock flows
2017-10-13T09:40:52Z DBG Packet number: 2
2017-10-13T09:40:52Z DBG decode packet data
2017-10-13T09:40:52Z DBG lock flows
2017-10-13T09:40:52Z DBG flowid: add eth
2017-10-13T09:40:52Z DBG IPv4 packet
2017-10-13T09:40:52Z DBG flowid: add ipv4
2017-10-13T09:40:52Z DBG TCP packet
2017-10-13T09:40:52Z DBG flowid: add tcp
2017-10-13T09:40:52Z DBG flow id flags: 1041
2017-10-13T09:40:52Z DBG get flow
2017-10-13T09:40:52Z DBG lookup flow: {1041 0 255 255 255 12 255 255 255 255 255 20 255 1 0 1} => [144 177 28 86 238 13 248 202 184 68 225 84 10 1 1 115 10 1 5 37 80 0 128 99]
2017-10-13T09:40:52Z DBG unlock flows
2017-10-13T09:40:52Z DBG Packet number: 3
2017-10-13T09:40:52Z DBG decode packet data
2017-10-13T09:40:52Z DBG lock flows
2017-10-13T09:40:52Z DBG flowid: add eth
2017-10-13T09:40:52Z DBG IPv4 packet
2017-10-13T09:40:52Z DBG flowid: add ipv4
2017-10-13T09:40:52Z DBG TCP packet
2017-10-13T09:40:52Z DBG flowid: add tcp
2017-10-13T09:40:52Z DBG flow id flags: 1041
2017-10-13T09:40:52Z DBG get flow
2017-10-13T09:40:52Z DBG lookup flow: {1041 0 255 255 255 12 255 255 255 255 255 20 255 1 0 1} => [144 177 28 86 238 13 248 202 184 68 225 84 10 1 1 115 10 1 5 37 80 0 128 99]
2017-10-13T09:40:52Z DBG unlock flows
2017-10-13T09:40:52Z DBG Packet number: 4
2017-10-13T09:40:52Z DBG decode packet data
2017-10-13T09:40:52Z DBG lock flows
2017-10-13T09:40:52Z DBG flowid: add eth
2017-10-13T09:40:52Z DBG IPv4 packet
2017-10-13T09:40:52Z DBG flowid: add ipv4
2017-10-13T09:40:52Z DBG TCP packet
2017-10-13T09:40:52Z DBG flowid: add tcp
2017-10-13T09:40:52Z DBG flow id flags: 1041
2017-10-13T09:40:52Z DBG get flow
2017-10-13T09:40:52Z DBG lookup flow: {1041 0 255 255 255 12 255 255 255 255 255 20 255 1 0 1} => [144 177 28 86 238 13 248 202 184 68 225 84 10 1 1 115 10 1 5 37 80 0 128 99]
2017-10-13T09:40:52Z DBG unlock flows
2017-10-13T09:40:52Z DBG Packet number: 5
2017-10-13T09:40:52Z DBG decode packet data
2017-10-13T09:40:52Z DBG lock flows
2017-10-13T09:40:52Z DBG flowid: add eth
2017-10-13T09:40:52Z DBG IPv4 packet
2017-10-13T09:40:52Z DBG flowid: add ipv4
2017-10-13T09:40:52Z DBG TCP packet
2017-10-13T09:40:52Z DBG flowid: add tcp
2017-10-13T09:40:52Z DBG flow id flags: 1041
2017-10-13T09:40:52Z DBG get flow
2017-10-13T09:40:52Z DBG lookup flow: {1041 0 255 255 255 12 255 255 255 255 255 20 255 1 0 1} => [144 177 28 86 238 13 248 202 184 68 225 84 10 1 1 115 10 1 5 37 80 0 128 99]
2017-10-13T09:40:52Z DBG unlock flows

```

[...]

 ![pcap_wshark](https://us1.discourse-cdn.com/elastic/original/3X/6/0/6031b79dc399c852e5e89da03d6ed61df3b7acc7.png)

thanks for your help

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 13, 2017, 1:30pm UTC](https://discuss.elastic.co/t/packetbeat-fails-to-extract-http-from-simple-pcap/103868/2 "2017-10-13T13:30:01Z")

</div>

How do you run packetbeat?

Are you looking at flows or are you refering to HTTP transactions from the HTTP module? Seems like you are more interested in the HTTP transactions.

HTTP is on top of TCP. The flows module only looks at src/dst + IP/Port address pairs + times out the flow if no more packets are seen in a TCP connection. Even TCP Reconnects with same ports might be counted into the same flow. There can be multiple HTTP transactions in one TCP connection.

---

<div class="post-metadata">

**Author:** ![theetete](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theetete/32/28298_2.png) [@theetete](https://discuss.elastic.co/u/theetete)\
**Post date:** [October 13, 2017, 2:40pm UTC](https://discuss.elastic.co/t/packetbeat-fails-to-extract-http-from-simple-pcap/103868/3 "2017-10-13T14:40:15Z")

</div>

Yes I had HTTP configured but found out it works better with specifying a port number in yml  
ports: [80]  
is there any way to catch all HTTP transaction regardless the port number, especially when reading from PCAP file ?

Now I got some results now but only halve of my requests are effectively stored in ES...  
I expect 4 HTTP req/resp documents but only got 2 ...

2017-10-13T14:35:21Z INFO Total non-zero values: libbeat.es.call\_count.PublishEvents=2 libbeat.es.publish.read\_bytes=1076 libbeat.es.publish.write\_bytes=3065 libbeat.es.published\_and\_acked\_events=2 libbeat.publisher.messages\_in\_worker\_queues=8 libbeat.publisher.published\_events=4

---

<div class="post-metadata">

**Author:** ![theetete](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theetete/32/28298_2.png) [@theetete](https://discuss.elastic.co/u/theetete)\
**Post date:** [October 13, 2017, 3:18pm UTC](https://discuss.elastic.co/t/packetbeat-fails-to-extract-http-from-simple-pcap/103868/4 "2017-10-13T15:18:50Z")

</div>

nvm, I fixed it with -waitstop 10 🙂

---

<div class="post-metadata">

**Author:** ![Samuel\_Lima1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samuel_lima1/32/101372_2.png) [@Samuel\_Lima1](https://discuss.elastic.co/u/Samuel_Lima1)\
**Post date:** [November 7, 2017, 3:21pm UTC](https://discuss.elastic.co/t/packetbeat-fails-to-extract-http-from-simple-pcap/103868/5 "2017-11-07T15:21:48Z")

</div>

Hi,  
How did you solve this problem?  
Where did you set up -waitstop 10 ?  
I didnt find this property in yml.

---

<div class="post-metadata">

**Author:** ![theetete](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theetete/32/28298_2.png) [@theetete](https://discuss.elastic.co/u/theetete)\
**Post date:** [November 7, 2017, 3:42pm UTC](https://discuss.elastic.co/t/packetbeat-fails-to-extract-http-from-simple-pcap/103868/6 "2017-11-07T15:42:31Z")

</div>

Hi,  
It's a command line option not a yml config

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 5, 2017, 3:42pm UTC](https://discuss.elastic.co/t/packetbeat-fails-to-extract-http-from-simple-pcap/103868/7 "2017-12-05T15:42:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
