# Packetbeats mechanism for capturing network flow data

**URL:** <https://discuss.elastic.co/t/packetbeats-mechanism-for-capturing-network-flow-data/246208>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [August 25, 2020, 2:40am UTC](https://discuss.elastic.co/t/packetbeats-mechanism-for-capturing-network-flow-data/246208 "2020-08-25T02:40:55Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![opentree](https://avatars.discourse-cdn.com/v4/letter/o/a6a055/32.png) [@opentree](https://discuss.elastic.co/u/opentree)\
**Post date:** [August 25, 2020, 2:40am UTC](https://discuss.elastic.co/t/packetbeats-mechanism-for-capturing-network-flow-data/246208/1 "2020-08-25T02:40:55Z")

</div>

I was wondering if someone could share how packetbeat captures network flow data. I tried to piece together from the documentation, but I was still unclear on a few things.

The documentation refers to the use of pcap or af\_packet for capturing network traffic (sniffing). For **flow monitoring** , does this also use the same mechanism to collect data?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2020, 4:41am UTC](https://discuss.elastic.co/t/packetbeats-mechanism-for-capturing-network-flow-data/246208/2 "2020-09-22T04:41:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
