# Packetbeat.yml with\_vlans cannot work?

**URL:** <https://discuss.elastic.co/t/packetbeat-yml-with-vlans-cannot-work/109340>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [November 28, 2017, 8:46am UTC](https://discuss.elastic.co/t/packetbeat-yml-with-vlans-cannot-work/109340 "2017-11-28T08:46:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefansaye](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@stefansaye](https://discuss.elastic.co/u/stefansaye)\
**Post date:** [November 28, 2017, 8:46am UTC](https://discuss.elastic.co/t/packetbeat-yml-with-vlans-cannot-work/109340/1 "2017-11-28T08:46:02Z")

</div>

Hello there,  
I will greatly appreciate help in making packetbeats work.  
I have add the option "with\_vlans" , but still not show vlan in my document  
How do I enable the option to packetbeat with\_vlans?

my packetbeat version:  
packetbeat version 5.5.2, libbeat 5.5.2

I have the following configuration.

```
packetbeat.interfaces.device: eth0
packetbeat.interfaces.snaplen: 1514
packetbeat.interfaces.type: af_packet
packetbeat.interfaces.buffer_size_mb: 100
packetbeat.interfaces.with_vlans: true
#================================== Flows =====================================
#Set `enabled: false` or comment out all options to disable flows reporting.
packetbeat.flows:
#Set network flow timeout. Flow is killed if no packet is received before being
# timed out.
timeout: 30s
# Configure reporting period. If set to -1, only killed flows will be reported
period: -1s
.............

```

Can you help?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 28, 2017, 10:22am UTC](https://discuss.elastic.co/t/packetbeat-yml-with-vlans-cannot-work/109340/2 "2017-11-28T10:22:06Z")

</div>

What are you monitoring? Is it a trunk line?

---

<div class="post-metadata">

**Author:** ![stefansaye](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@stefansaye](https://discuss.elastic.co/u/stefansaye)\
**Post date:** [November 29, 2017, 5:40am UTC](https://discuss.elastic.co/t/packetbeat-yml-with-vlans-cannot-work/109340/3 "2017-11-29T05:40:27Z")

</div>

@andrewkroh  
I'm monitor from kibana

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 29, 2017, 2:35pm UTC](https://discuss.elastic.co/t/packetbeat-yml-with-vlans-cannot-work/109340/4 "2017-11-29T14:35:10Z")

</div>

> [@andrewkroh](#):
>
> What are you monitoring? Is it a trunk line?

> [@stefansaye](#):
>
> I'm monitor from kibana

No, what sort of the network traffic are you monitoring? Is this a trunk line with tagged traffic?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2017, 2:35pm UTC](https://discuss.elastic.co/t/packetbeat-yml-with-vlans-cannot-work/109340/5 "2017-12-27T14:35:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
