# Packetbeat performance SPAN

**URL:** https://discuss.elastic.co/t/packetbeat-performance-span/98250
**Category:** Beats
**Tags:** packetbeat
**Created:** [August 24, 2017, 2:32pm UTC](https://discuss.elastic.co/t/packetbeat-performance-span/98250 "2017-08-24T14:32:35Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![cmqv](https://avatars.discourse-cdn.com/v4/letter/c/f04885/32.png) [@cmqv](https://discuss.elastic.co/u/cmqv)
#### Post date: [August 24, 2017, 2:32pm UTC](https://discuss.elastic.co/t/packetbeat-performance-span/98250/1 "2017-08-24T14:32:35Z")

</div>

I'd want to evaluate the use of packetbeat to pickup traffic from a SPAN port.  
(i have no idea what my traffic output from the SPAN port is, but i assume somewhere around 10Gbps)

I assume i will compile against the pf\_ring (library?) for fastest performance.

I've searched through historic threads and cant find much about Packets-per-Second performance of packetbeat (with any of the options af\_ring, pf\_ring or pcap).

Could anybody help me outline a test setup for packetbeat  
The main thing i'm struggling with is creating an endpoint for packetbeat's output. The obvious thing to use is an Elasticsearch cluster,... but i'd like to know that i'm keeping my elasticsearch indexing performance and packetbeat packets-per-second processing as two separate questions.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 21, 2017, 2:32pm UTC](https://discuss.elastic.co/t/packetbeat-performance-span/98250/2 "2017-09-21T14:32:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
