# Response Time, Flows and New Transaction Protocol

**URL:** <https://discuss.elastic.co/t/response-time-flows-and-new-transaction-protocol/170671>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [March 4, 2019, 5:34am UTC](https://discuss.elastic.co/t/response-time-flows-and-new-transaction-protocol/170671 "2019-03-04T05:34:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nandrik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nandrik/32/39951_2.png) [@nandrik](https://discuss.elastic.co/u/nandrik)\
**Post date:** [March 4, 2019, 5:34am UTC](https://discuss.elastic.co/t/response-time-flows-and-new-transaction-protocol/170671/1 "2019-03-04T05:34:37Z")

</div>

I've read the post: [Finding total latency(round trip time or response time) per flow?](https://discuss.elastic.co/t/finding-total-latency-round-trip-time-or-response-time-per-flow/154971)

I want to be able for a new transaction protocol, call it **elastic** which transacts on port: **2019** to be able to calculate response times but also be able to still see flow statistics.

- Is it possible to have both flow statistics and tranaction protocol metrics?
- If so, what are the critical config settings in packetbeat.yml to achieve this?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 8, 2019, 2:36pm UTC](https://discuss.elastic.co/t/response-time-flows-and-new-transaction-protocol/170671/2 "2019-03-08T14:36:15Z")

</div>

Packetbeat has a finite set of protocols that it understands (see [docs](https://www.elastic.co/guide/en/beats/packetbeat/current/packetbeat-overview.html)). In order to measure response time Packetbeat needs to understand the protocol to know when a request and response are sent.

So if the protocol isn't one of the ones that Packetbeat has a decoder for then you can cannot get response times without implementing a custom decoder and building your own Packetbeat (or contributing the decoder).

You can measure generic flow stats only for traffic on port 2019 by setting a custom filter ([docs](https://www.elastic.co/guide/en/beats/packetbeat/6.6/configuration-interfaces.html#_literal_bpf_filter_literal)). Note that is overrides the packet filter for all of Packetbeat so if you enable the DNS protocol, for example, you will need to add port 53 into the filter manually.

```auto
packetbeat.interfaces.bpf_filter: "port 2012"
packetbeat.flows.enabled: true

```

---

<div class="post-metadata">

**Author:** ![nandrik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nandrik/32/39951_2.png) [@nandrik](https://discuss.elastic.co/u/nandrik)\
**Post date:** [March 8, 2019, 8:55pm UTC](https://discuss.elastic.co/t/response-time-flows-and-new-transaction-protocol/170671/3 "2019-03-08T20:55:06Z")

</div>

I get it, so if I want to get both flow stats and protocol (say http) response time, I need to do something like this:

```auto
packetbeat.interfaces.device: any
packetbeat.interfaces.bpf_filter: "port 2019" 
- type: http
  ports: [2019]
  enabled: true

```

Is this right?  
Is there an easy way to know if I'm missing any other protocols that exist in the flows?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2019, 8:55pm UTC](https://discuss.elastic.co/t/response-time-flows-and-new-transaction-protocol/170671/4 "2019-04-05T20:55:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
