# Packetbeat not starting after standby

**URL:** https://discuss.elastic.co/t/packetbeat-not-starting-after-standby/119034
**Category:** Beats
**Tags:** packetbeat
**Created:** [February 8, 2018, 12:09pm UTC](https://discuss.elastic.co/t/packetbeat-not-starting-after-standby/119034 "2018-02-08T12:09:08Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![Vincent\_Maury](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vincent_maury/32/59973_2.png) [@Vincent\_Maury](https://discuss.elastic.co/u/Vincent_Maury)
#### Post date: [February 8, 2018, 12:09pm UTC](https://discuss.elastic.co/t/packetbeat-not-starting-after-standby/119034/1 "2018-02-08T12:09:08Z")

</div>

I have packetbeat 6.1.2 installed as a service, running fine, but when I turn my laptop in standby (closing it) and I wake it up, packetbeat would not start.  
I can start it manually.  
And all 3 other beats that I installed the same way (audit, metric and winlog) are starting fine...  
Thanks in advance for your help!

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [February 8, 2018, 11:59pm UTC](https://discuss.elastic.co/t/packetbeat-not-starting-after-standby/119034/2 "2018-02-08T23:59:48Z")

</div>

How can you tell packetbeat does not startup anymore?

Which operating system are you using?

I wonder if packetbeat actually starts, but can not sniff from device anymore. Might be a kernel issue... which device and sniffer type are you using?

---

<div class="post-metadata">

### Author: ![Vincent\_Maury](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vincent_maury/32/59973_2.png) [@Vincent\_Maury](https://discuss.elastic.co/u/Vincent_Maury)
#### Post date: [February 9, 2018, 11:08am UTC](https://discuss.elastic.co/t/packetbeat-not-starting-after-standby/119034/3 "2018-02-09T11:08:53Z")

</div>

Hi Steffen,  
I'm running Windows 10 Pro (Version 10.0.16299 number 16299)  
I know it doesn't run because when I check my services, it's "stopped". And I can start it again.  
After running a few tests, it appears there is an error in windows events saying that the packetbeat service has stopped unexpectedly every time I close my laptop (goes in stand by mode).  
Note that my packetbeat is configured to send data to a cluster I have on Elastic Cloud.

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [February 9, 2018, 2:05pm UTC](https://discuss.elastic.co/t/packetbeat-not-starting-after-standby/119034/4 "2018-02-09T14:05:23Z")

</div>

Have you checked packetbeat logs for errors? Please run packetbeat in debug mode. Debug selector 'service' should enough.

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [February 9, 2018, 2:16pm UTC](https://discuss.elastic.co/t/packetbeat-not-starting-after-standby/119034/5 "2018-02-09T14:16:47Z")

</div>

Can you run packetbeat on foreground, in terminal. In case packetbeat crashes/breaks after a sleep this info will be lost when being run as a service. For testing please run packetbeat in terminal with `packetbeat.exe -e -v -d '*' -c <path/to/config/file>`, but you machine to sleep and wake up after a while.

---

<div class="post-metadata">

### Author: ![Vincent\_Maury](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vincent_maury/32/59973_2.png) [@Vincent\_Maury](https://discuss.elastic.co/u/Vincent_Maury)
#### Post date: [February 9, 2018, 4:16pm UTC](https://discuss.elastic.co/t/packetbeat-not-starting-after-standby/119034/6 "2018-02-09T16:16:43Z")

</div>

Here you go (i replaced my cloud id with xxx) :  
C:\Users\Vincent\Documents\tech\Beats\packetbeat-6.1.2-windows-x86\_64\>packetbeat.exe -e -v -d '\*'  
packetbeat2018/02/09 16:13:18.850794 cloudid.go:42: INFO Setting Elasticsearch and Kibana URLs based on the cloud id: output.elasticsearch.hosts=https://xxx.europe-west1.gcp.cloud.es.io:443 and setup.kibana.host=https://xxx.europe-west1.gcp.cloud.es.io:443  
2018/02/09 16:13:18.851764 beat.go:436: INFO Home path: [C:\Users\Vincent\Documents\tech\Beats\packetbeat-6.1.2-windows-x86\_64] Config path: [C:\Users\Vincent\Documents\tech\Beats\packetbeat-6.1.2-windows-x86\_64] Data path: [C:\Users\Vincent\Documents\tech\Beats\packetbeat-6.1.2-windows-x86\_64\data] Logs path: [C:\Users\Vincent\Documents\tech\Beats\packetbeat-6.1.2-windows-x86\_64\logs]  
2018/02/09 16:13:18.851764 metrics.go:23: INFO Metrics logging every 30s  
2018/02/09 16:13:18.851764 beat.go:443: INFO Beat UUID: cf165164-009a-4ca6-87a7-884c342289c3  
2018/02/09 16:13:18.851764 beat.go:203: INFO Setup Beat: packetbeat; Version: 6.1.2  
2018/02/09 16:13:18.851764 client.go:123: INFO Elasticsearch url: [https://xxx.europe-west1.gcp.cloud.es.io:443](https://xxx.europe-west1.gcp.cloud.es.io:443)  
2018/02/09 16:13:18.852799 module.go:76: INFO Beat name: VINCENT-ELASTIC  
2018/02/09 16:13:18.853769 procs.go:78: INFO Process matching disabled  
2018/02/09 16:13:18.923953 device.go:75: INFO Resolved device index 0 to device: \Device\NPF\_{A3F4F9AE-D5C1-4F4A-91EC-9D32DB0ACC19}  
2018/02/09 16:13:18.923953 beat.go:276: INFO packetbeat start running.  
2018/02/09 16:13:21.116784 client.go:651: INFO Connected to Elasticsearch version 6.1.3  
2018/02/09 16:13:21.130820 load.go:73: INFO Template already exists and will not be overwritten.  
2018/02/09 16:13:48.852770 metrics.go:39: INFO Non-zero metrics in the last 30s: beat.info.uptime.ms=30030 beat.memstats.gc\_next=35889440 beat.memstats.memory\_alloc=21780456 beat.memstats.memory\_total=25667944 dns.unmatched\_responses=1 libbeat.config.module.running=0 libbeat.output.read.bytes=4134 libbeat.output.type=elasticsearch libbeat.output.write.bytes=71062 libbeat.pipeline.clients=14 libbeat.pipeline.events.active=0 libbeat.pipeline.events.published=92 libbeat.pipeline.events.retry=2 libbeat.pipeline.events.total=92 libbeat.pipeline.queue.acked=92  
2018/02/09 16:14:05.246181 util.go:47: INFO flows worker loop stopped  
2018/02/09 16:14:05.246181 metrics.go:51: INFO Total non-zero values: beat.info.uptime.ms=46423 beat.memstats.gc\_next=35889440 beat.memstats.memory\_alloc=26041440 beat.memstats.memory\_total=29928928 dns.unmatched\_responses=2 libbeat.config.module.running=0 libbeat.output.read.bytes=8971 libbeat.output.type=elasticsearch libbeat.output.write.bytes=180466 libbeat.pipeline.clients=14 libbeat.pipeline.events.active=156 libbeat.pipeline.events.published=411 libbeat.pipeline.events.retry=2 libbeat.pipeline.events.total=411 libbeat.pipeline.queue.acked=255  
2018/02/09 16:14:14.880555 metrics.go:52: INFO Uptime: 56.0578707s  
2018/02/09 16:14:14.882560 beat.go:284: INFO packetbeat stopped.  
2018/02/09 16:14:14.883567 beat.go:635: CRIT Exiting: Sniffer main loop failed: Sniffing error: Read Error  
Exiting: Sniffer main loop failed: Sniffing error: Read Error

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [February 9, 2018, 6:40pm UTC](https://discuss.elastic.co/t/packetbeat-not-starting-after-standby/119034/7 "2018-02-09T18:40:32Z")

</div>

Please format logs, configs and terminal input/output using the `</>`-Button or [markdown code fences](https://help.github.com/articles/creating-and-highlighting-code-blocks/#fenced-code-blocks). This forum uses Markdown to format posts. Without proper formatting, it can be very hard to read your posts.

The last message indicates why packetbeat stops:

```auto
2018/02/09 16:14:14.883567 beat.go:635: CRIT Exiting: Sniffer main loop failed: Sniffing error: Read Error

```

It gets an `Read Error` from WinPCAP (just assuming you use WinPCAP) and there shuts down. I guess the network adapter is not yet ready, while packetbeat is trying to continue sniffing.

---

<div class="post-metadata">

### Author: ![Vincent\_Maury](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vincent_maury/32/59973_2.png) [@Vincent\_Maury](https://discuss.elastic.co/u/Vincent_Maury)
#### Post date: [February 12, 2018, 2:06pm UTC](https://discuss.elastic.co/t/packetbeat-not-starting-after-standby/119034/8 "2018-02-12T14:06:38Z")

</div>

Sorry Steffens for the poor formatting  
I solved my issue! indeed it was coming from winpcap  
winpcap doesn't work on Windows 10  
I used the win10pcap (see [http://www.win10pcap.org/](http://www.win10pcap.org/) ) which is working fine!  
Thanks for your support 🙂

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 12, 2018, 2:06pm UTC](https://discuss.elastic.co/t/packetbeat-not-starting-after-standby/119034/9 "2018-03-12T14:06:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
