# Reading packets from pcap file

**URL:** <https://discuss.elastic.co/t/reading-packets-from-pcap-file/26278>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [July 25, 2015, 12:39am UTC](https://discuss.elastic.co/t/reading-packets-from-pcap-file/26278 "2015-07-25T00:39:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![catwallader](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/catwallader/32/1043_2.png) [@catwallader](https://discuss.elastic.co/u/catwallader)\
**Post date:** [July 25, 2015, 12:39am UTC](https://discuss.elastic.co/t/reading-packets-from-pcap-file/26278/1 "2015-07-25T00:39:50Z")

</div>

Is it possible to read packets from an exiting pcap file. I see that packetbeat has a -I option, which I thought would be an input file, but it doesn't seem to be.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [July 27, 2015, 8:47am UTC](https://discuss.elastic.co/t/reading-packets-from-pcap-file/26278/2 "2015-07-27T08:47:27Z")

</div>

That's right, the `-I` option does that. Here is an example:

```
./packetbeat -e -c packetbeat.dev.yml -t -I tests/pcaps/http_post.pcap -d "publish"

```

The `-t` means reading the packets as fast as possible (as opposed to replaying them at the time intervals from the capture).

We use these options mostly for development and automatic tests, but they should work also for indexing pcap files.

---

<div class="post-metadata">

**Author:** ![catwallader](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/catwallader/32/1043_2.png) [@catwallader](https://discuss.elastic.co/u/catwallader)\
**Post date:** [July 27, 2015, 6:52pm UTC](https://discuss.elastic.co/t/reading-packets-from-pcap-file/26278/3 "2015-07-27T18:52:54Z")

</div>

Hi tudor.

I tried your command, but it isn't work for me. I just ended up capturing  
packets from the wire for the few milliseconds that packetbeat ran.

Also, I don't see individual packets, which I guess makes sense since  
packetbeat is following high level protocol flows, http, etc. However if  
packetbeat had a mode to capture individual packets that would be more  
useful to me. IS there a way to do that with packetbeat?

Cheers,

---

<div class="post-metadata">

**Author:** ![catwallader](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/catwallader/32/1043_2.png) [@catwallader](https://discuss.elastic.co/u/catwallader)\
**Post date:** [July 27, 2015, 7:52pm UTC](https://discuss.elastic.co/t/reading-packets-from-pcap-file/26278/4 "2015-07-27T19:52:32Z")

</div>

Hi again Tudor.

Correction, packetbeat does read in pcap files if there are app protocol  
requests and responses. The packet capture I mentioned earlier was just  
raw TCP packets, at least in Wireshark the only protocol identified was  
TCP. But for another capture I did there was an HTTP request and response  
that packetbeat got.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [July 28, 2015, 8:49am UTC](https://discuss.elastic.co/t/reading-packets-from-pcap-file/26278/5 "2015-07-28T08:49:30Z")

</div>

Right, Packetbeat only publishes when it sees a request-response pair. You can make it save pcap files, btw, with the `-dump` option.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:59pm UTC](https://discuss.elastic.co/t/reading-packets-from-pcap-file/26278/6 "2017-07-05T21:59:03Z")

</div>


