# Packetbeat for Windows does not capture TCP port data.?

**URL:** https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965
**Category:** Beats
**Tags:** packetbeat
**Created:** [March 21, 2016, 9:14am UTC](https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965 "2016-03-21T09:14:50Z")
**Posts on this page:** 13
**Page:** 1

<div class="post-metadata">

### Author: ![talk2cshah](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@talk2cshah](https://discuss.elastic.co/u/talk2cshah)
#### Post date: [March 21, 2016, 9:14am UTC](https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965/1 "2016-03-21T09:14:50Z")

</div>

Dear Team,

Basis the link below

> <https://github.com/elastic/beats/issues/104>

Packetbeat does not capture packets on TCP port on Windows.

and current issue I am facing on my local instance is that packet beat does not capture TCP port Windows7 64bit

packets e.g. mysql running on port 3306.

Has anyone succefully installed and captured TCP packets on windows?

Kindly guide.

Regards, Chirag Shah

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [March 21, 2016, 11:31am UTC](https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965/2 "2016-03-21T11:31:18Z")

</div>

You just trying to sniff mysql? Is mysql client using TCP connection or names pipe (default)?

---

<div class="post-metadata">

### Author: ![talk2cshah](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@talk2cshah](https://discuss.elastic.co/u/talk2cshah)
#### Post date: [March 21, 2016, 11:32am UTC](https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965/3 "2016-03-21T11:32:38Z")

</div>

Tcp connection!

---

<div class="post-metadata">

### Author: ![talk2cshah](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@talk2cshah](https://discuss.elastic.co/u/talk2cshah)
#### Post date: [March 21, 2016, 4:51pm UTC](https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965/4 "2016-03-21T16:51:21Z")

</div>

Guys, has anyone configured packetbeat to listen tcp ports on Windows? or is it a known issue?

Regards, Chirag Shah

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [March 21, 2016, 11:14pm UTC](https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965/5 "2016-03-21T23:14:40Z")

</div>

WinPcap cannot capture from the loopback device (127.0.0.1 traffic). See my comment [here](https://github.com/elastic/beats/issues/104#issuecomment-199525840) for details on the work around.

---

<div class="post-metadata">

### Author: ![White\_Tong](https://avatars.discourse-cdn.com/v4/letter/w/ecae2f/32.png) [@White\_Tong](https://discuss.elastic.co/u/White_Tong)
#### Post date: [November 15, 2016, 9:12am UTC](https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965/6 "2016-11-15T09:12:59Z")

</div>

Hey andrewkroh.  
I tried npcap v0.10-r18 on Windows 7 but the Packetbeat does not capture traffic from the loopback interface.  
However, Wrieshar can capture mysql data from Npcap Loopback Adapter such as the icon below.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/c2bb9ab9dbb34c614ad1a2a4824096a75bf0da2a.gif)

The following snippet shows my configuration.

> ############################# Sniffer #########################################

> interfaces:  
> device: 1  
> buffer\_size\_mb: 100

> ############################# Protocols #######################################  
> protocols:  
> dns:
> 
> ```
> ports: [53]
> 
> ```

> ```
> include_authorities: true
> include_additionals: true
> 
> ```

> ```
> # send_request: true
> # send_response: true
> 
> ```

> http:

> ```
> ports: [80, 8080, 8000, 5000, 8002]
> 
> ```

> memcache:

> ```
> ports: [11211]
> 
> ```

> mysql:

> ```
> ports: [3306]
> 
> ```

> pgsql:

> ```
> ports: [5432]
> 
> ```

> redis:

> ```
> ports: [6379]
> 
> ```

> thrift:

> ```
> ports: [9090]
> 
> ```

> mongodb:
> 
> ```
> ports: [27017]
> 
> ```

> ############################# Processes #######################################

> procs:  
> enabled: true  
> monitored:  
> - process: mysqld  
> cmdline\_grep: mysqld

> ```
> - process: app
> cmdline_grep: gunicorn
> 
> ```

> ###############################################################################  
> ############################# Libbeat Config ##################################
> 
> # Base config file used by all other beats for using libbeat features

> ############################# Output ##########################################

> # Configure what outputs to use when sending the data collected by the beat.
> 
> # Multiple outputs may be used.
> 
> output:

> logstash:  
> hosts: ["localhost:5044"]

> ############################# Shipper #########################################

> shipper:  
> name: "172.16.7.163"

> ############################# Logging #########################################

> logging:  
> files:  
> rotateeverybytes: 10485760 # = 10MB # Number of rotated log files to keep. Oldest files will be deleted first.

![](https://us1.discourse-cdn.com/elastic/original/2X/7/7235ffd3be76a90cae70c84d3575012c9ced2e3a.gif)

The following icon shows the MySQL.  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/0c3b5a75374c4b5fb5af25c8ddf0699f09242a4f.gif)

```
  packetbeat -e -d "publish" -N
  select * from XXX;

```

 ![](https://us1.discourse-cdn.com/elastic/original/2X/f/fd326ff1585597aaa46a60d6d4d4c8ec60d37db2.gif)

Packetbeat does not capture traffic.

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [November 15, 2016, 3:22pm UTC](https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965/7 "2016-11-15T15:22:25Z")

</div>

Shouldn't the device be called "Npcap Loopback Adapter"? It looks like that is what your Wireshark is reading from based on the Window title. Did you re-run `-devices` after installing the driver? Maybe the machine needs a reboot after installing the driver.

---

<div class="post-metadata">

### Author: ![White\_Tong](https://avatars.discourse-cdn.com/v4/letter/w/ecae2f/32.png) [@White\_Tong](https://discuss.elastic.co/u/White_Tong)
#### Post date: [November 16, 2016, 2:38am UTC](https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965/8 "2016-11-16T02:38:51Z")

</div>

Thanks for your support. I'm sure the machine has been restarted after installing the driver. Unfortunately, the wrieshark can capture the traffic from Npcap Loopback adapter but packetbeat can't. I tried it again, but the result likes before.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/8/87aae288f266b7f52a29b0ba01ed1f9d700d358b.gif)

I change configuration to “devices:2”，and packetbeat can only capture data type "dns" or "http". But my goal is to get the performance of mysql.  
Please guide me about that, thanks!

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [November 16, 2016, 2:56am UTC](https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965/9 "2016-11-16T02:56:11Z")

</div>

Did you install Npcap with "WinPcap Compatible Mode"? Did you uninstall winpcap?

The fact that the interface is called "MS LoopBack Driver" seems to indicate that Packetbeat is not using Npcap.

---

<div class="post-metadata">

### Author: ![White\_Tong](https://avatars.discourse-cdn.com/v4/letter/w/ecae2f/32.png) [@White\_Tong](https://discuss.elastic.co/u/White_Tong)
#### Post date: [November 16, 2016, 8:00am UTC](https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965/10 "2016-11-16T08:00:35Z")

</div>

Thank you very much, I have reinstalled Npcap with "WinPcap Compatible Mode". Now, the packetbeat works well.  
Althought the traffics of mysql can be captured, HTTP&DNS are lost.  
Do you know how to capture all of them? Thanks!

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [November 16, 2016, 9:22am UTC](https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965/11 "2016-11-16T09:22:14Z")

</div>

Is traffic send on different interfaces? Like HTTP/DNS being accessed from the outside and mysql from the inside, in such a way traffic can only be captured by different interfaces (Sorry, I'm no windows expert). In this case, right now, you have to run 2 packetbeat instances. Also watch this [enhancement request](https://github.com/elastic/beats/issues/263).

---

<div class="post-metadata">

### Author: ![White\_Tong](https://avatars.discourse-cdn.com/v4/letter/w/ecae2f/32.png) [@White\_Tong](https://discuss.elastic.co/u/White_Tong)
#### Post date: [November 16, 2016, 11:22am UTC](https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965/12 "2016-11-16T11:22:23Z")

</div>

Yeah, you are right.  
Thanks for your support!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 9:50pm UTC](https://discuss.elastic.co/t/packetbeat-for-windows-does-not-capture-tcp-port-data/44965/13 "2017-07-05T21:50:16Z")

</div>


