# Setting up Packetbeat/Elasticsearch/kibana

**URL:** <https://discuss.elastic.co/t/setting-up-packetbeat-elasticsearch-kibana/20436>\
**Category:** Elasticsearch\
**Created:** [October 26, 2014, 8:13pm UTC](https://discuss.elastic.co/t/setting-up-packetbeat-elasticsearch-kibana/20436 "2014-10-26T20:13:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sarah\_Larysz](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@Sarah\_Larysz](https://discuss.elastic.co/u/Sarah_Larysz)\
**Post date:** [October 26, 2014, 8:13pm UTC](https://discuss.elastic.co/t/setting-up-packetbeat-elasticsearch-kibana/20436/1 "2014-10-26T20:13:58Z")

</div>

I have set up Packetbeat/Elasticsearch/kibana on a Windows 2012 server as  
per the instructions.

1: The rev of Kibana is 3.1.1.  
2: Packetbeat is collecting some kind of data and indexes have been  
created in Elasticsearch.  
3: A web browser pointing to the Elasticsearch source responds with a  
JASON object listing.  
4: Kibana shows a generic dashboard, but there is no listing of dashboards  
under "load" and I don't know if kibana is seeing any data at all from  
packetbeat.

What have I done wrong, and how can I test for packetbeat data? Here's my  
site:

_[http://gazoslive.com/kibana/#/dashboard/file/default.json](http://gazoslive.com/kibana/#/dashboard/file/default.json)_

Here is my config.js file (though I cannot find where in the javascript  
code this file is read):

_/_\* @scratch /configuration/config.js/1 \* \* == Configuration \* config.js  
is where you will find the core Kibana configuration. This file contains  
parameter that \* must be set before kibana is run for the first  
time. _/define(['settings'],function (Settings) { /_\* @scratch  
/configuration/config.js/2 \* \* === Parameters _/ return new  
Settings({ /_\* @scratch /configuration/config.js/5 \* \* ====  
elasticsearch \* \* The URL to your elasticsearch server. You almost  
certainly don't \* want +http://localhost:9200+ here. Even if Kibana and  
Elasticsearch are on \* the same host. By default this will attempt to  
reach ES at the same host you have \* kibana installed on. You probably  
want to set it to the FQDN of your \* elasticsearch host \* \*  
Note: this can also be an object if you want to pass options to the http  
client. For example: \* \* +elasticsearch: {server:  
"[http://localhost:9200](http://localhost:9200)", withCredentials: true}+ \* \* elasticsearch:  
"http://"+window.location.hostname+":9200", \* _/ elasticsearch:  
"[http://ihpgazos.cloudapp.net:9200](http://ihpgazos.cloudapp.net:9200)", /_\* @scratch  
/configuration/config.js/5 \* \* ==== default\_route \* \* This  
is the default landing page when you don't specify a dashboard to load. You  
can specify \* files, scripts or saved dashboards here. For example, if  
you had saved a dashboard called \* `WebLogs' to elasticsearch you might  
use: \* \* default\_route: '/dashboard/elasticsearch/WebLogs',  
_/ default\_route : '/dashboard/file/default.json', /_\* @scratch  
/configuration/config.js/5 \* \* ==== kibana-int \* \* The  
default ES index to use for storing Kibana specific object \* such as  
stored dashboards _/ kibana\_index: "kibana-int", /_\* @scratch  
/configuration/config.js/5 \* \* ==== panel\_name \* \* An array  
of panel modules available. Panels will only be loaded when they are  
defined in the \* dashboard, but this list is used in the "add panel"  
interface. _/ panel\_names: [ 'histogram', 'map',  
'goal', 'table', 'filtering', 'timepicker',  
'text', 'hits', 'column', 'trends', 'bettermap',  
'query', 'terms', 'stats', 'sparklines' ] });});_

All suggestions will be valued.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0fe67bc4-d778-4ca6-a967-6e2033cc2f9a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0fe67bc4-d778-4ca6-a967-6e2033cc2f9a%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 26, 2014, 8:31pm UTC](https://discuss.elastic.co/t/setting-up-packetbeat-elasticsearch-kibana/20436/2 "2014-10-26T20:31:13Z")

</div>

Opening up ES to the world is asking for a lot of pain. You really need to  
lock it down.

Did you install kibana from the PB repo and load the dashboards script?

On 27 October 2014 07:13, Sarah Larysz [slarysz@gazos.com](mailto:slarysz@gazos.com) wrote:

> I have set up Packetbeat/Elasticsearch/kibana on a Windows 2012 server as  
> per the instructions.
> 
> 1: The rev of Kibana is 3.1.1.  
> 2: Packetbeat is collecting some kind of data and indexes have been  
> created in Elasticsearch.  
> 3: A web browser pointing to the Elasticsearch source responds with a  
> JASON object listing.  
> 4: Kibana shows a generic dashboard, but there is no listing of  
> dashboards under "load" and I don't know if kibana is seeing any data at  
> all from packetbeat.
> 
> What have I done wrong, and how can I test for packetbeat data? Here's my  
> site:
> 
> _[http://gazoslive.com/kibana/#/dashboard/file/default.json](http://gazoslive.com/kibana/#/dashboard/file/default.json)  
> [http://gazoslive.com/kibana/#/dashboard/file/default.json](http://gazoslive.com/kibana/#/dashboard/file/default.json)_
> 
> Here is my config.js file (though I cannot find where in the javascript  
> code this file is read):
> 
> _/_\* @scratch /configuration/config.js/1 \* \* == Configuration \* config.js  
> is where you will find the core Kibana configuration. This file contains  
> parameter that \* must be set before kibana is run for the first  
> time. _/define(['settings'],function (Settings) { /_\* @scratch  
> /configuration/config.js/2 \* \* === Parameters _/ return new  
> Settings({ /_\* @scratch /configuration/config.js/5 \* \* ====  
> elasticsearch \* \* The URL to your elasticsearch server. You almost  
> certainly don't \* want +http://localhost:9200+ here. Even if Kibana and  
> Elasticsearch are on \* the same host. By default this will attempt to  
> reach ES at the same host you have \* kibana installed on. You probably  
> want to set it to the FQDN of your \* elasticsearch host \* \*  
> Note: this can also be an object if you want to pass options to the http  
> client. For example: \* \* +elasticsearch: {server:  
> "[http://localhost:9200](http://localhost:9200) [http://localhost:9200](http://localhost:9200)", withCredentials: true}+
> 
> - 
> 
> ```
> * elasticsearch: "http://"+window.location.hostname+":9200",
> 
> ```
> 
> - 
> 
> ```
> */ elasticsearch: "http://ihpgazos.cloudapp.net:9200
> 
> ```
> 
> [http://ihpgazos.cloudapp.net:9200](http://ihpgazos.cloudapp.net:9200)", /\*\* @scratch  
> /configuration/config.js/5 \* \* ==== default\_route \* \* This  
> is the default landing page when you don't specify a dashboard to load. You  
> can specify \* files, scripts or saved dashboards here. For example, if  
> you had saved a dashboard called \* `WebLogs' to elasticsearch you might  
> use: \* \* default\_route: '/dashboard/elasticsearch/WebLogs',  
> _/ default\_route : '/dashboard/file/default.json', /_\* @scratch  
> /configuration/config.js/5 \* \* ==== kibana-int \* \* The  
> default ES index to use for storing Kibana specific object \* such as  
> stored dashboards _/ kibana\_index: "kibana-int", /_\* @scratch  
> /configuration/config.js/5 \* \* ==== panel\_name \* \* An array  
> of panel modules available. Panels will only be loaded when they are  
> defined in the \* dashboard, but this list is used in the "add panel"  
> interface. _/ panel\_names: [ 'histogram', 'map',  
> 'goal', 'table', 'filtering', 'timepicker',  
> 'text', 'hits', 'column', 'trends', 'bettermap',  
> 'query', 'terms', 'stats', 'sparklines' ] });});_
> 
> All suggestions will be valued.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/0fe67bc4-d778-4ca6-a967-6e2033cc2f9a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0fe67bc4-d778-4ca6-a967-6e2033cc2f9a%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/0fe67bc4-d778-4ca6-a967-6e2033cc2f9a%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/0fe67bc4-d778-4ca6-a967-6e2033cc2f9a%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAF3ZnZmvhqiWXsctSmi2fRiO%2Bhyhz71A44vDN6Y%2BxrEifrxgkQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAF3ZnZmvhqiWXsctSmi2fRiO%2Bhyhz71A44vDN6Y%2BxrEifrxgkQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Tudor\_Golubenco](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor_golubenco/32/1172_2.png) [@Tudor\_Golubenco](https://discuss.elastic.co/u/Tudor_Golubenco)\
**Post date:** [October 27, 2014, 10:56am UTC](https://discuss.elastic.co/t/setting-up-packetbeat-elasticsearch-kibana/20436/3 "2014-10-27T10:56:54Z")

</div>

Hi Sarah,

It looks to me like you installed the default Kibana3 instead of the  
extended Kibana version (which has a few panels specific for Packetbeat).  
You can download it from  
here: [Release Kibana 3.1.0 with Packetbeat addons · packetb-old/kibana · GitHub](https://github.com/packetbeat/kibana/releases/tag/v3.1.0-pb)

You can still view the dashboards by selecting them from the Load menu. For  
example: http://--redacted--.com/kibana/#/dashboard/elasticsearch/Packetbeat%2520Statistics  
It seems to be working fine, it's just the extra widgets that don't work.

Like Mark said, please don't leave this instance open to the world. Because  
of the network traffic visibility that Packetbeat provides you are quite  
likely to leak information.

Best Regards,  
Tudor

On Sunday, October 26, 2014 9:13:58 PM UTC+1, Sarah Larysz wrote:

> I have set up Packetbeat/Elasticsearch/kibana on a Windows 2012 server as  
> per the instructions.
> 
> 1: The rev of Kibana is 3.1.1.  
> 2: Packetbeat is collecting some kind of data and indexes have been  
> created in Elasticsearch.  
> 3: A web browser pointing to the Elasticsearch source responds with a  
> JASON object listing.  
> 4: Kibana shows a generic dashboard, but there is no listing of  
> dashboards under "load" and I don't know if kibana is seeing any data at  
> all from packetbeat.
> 
> What have I done wrong, and how can I test for packetbeat data? Here's my  
> site:
> 
> _[http://gazoslive.com/kibana/#/dashboard/file/default.json](http://gazoslive.com/kibana/#/dashboard/file/default.json)  
> [http://gazoslive.com/kibana/#/dashboard/file/default.json](http://gazoslive.com/kibana/#/dashboard/file/default.json)_
> 
> Here is my config.js file (though I cannot find where in the javascript  
> code this file is read):
> 
> _/_\* @scratch /configuration/config.js/1 \* \* == Configuration \* config.js  
> is where you will find the core Kibana configuration. This file contains  
> parameter that \* must be set before kibana is run for the first  
> time. _/define(['settings'],function (Settings) { /_\* @scratch  
> /configuration/config.js/2 \* \* === Parameters _/ return new  
> Settings({ /_\* @scratch /configuration/config.js/5 \* \* ====  
> elasticsearch \* \* The URL to your elasticsearch server. You almost  
> certainly don't \* want +http://localhost:9200+ here. Even if Kibana and  
> Elasticsearch are on \* the same host. By default this will attempt to  
> reach ES at the same host you have \* kibana installed on. You probably  
> want to set it to the FQDN of your \* elasticsearch host \* \*  
> Note: this can also be an object if you want to pass options to the http  
> client. For example: \* \* +elasticsearch: {server:  
> "[http://localhost:9200](http://localhost:9200) [http://localhost:9200](http://localhost:9200)", withCredentials: true}+
> 
> - 
> 
> ```
> * elasticsearch: "http://"+window.location.hostname+":9200",     
> 
> ```
> 
> - 
> 
> ```
> */ elasticsearch: "http://ihpgazos.cloudapp.net:9200 
> 
> ```
> 
> [http://ihpgazos.cloudapp.net:9200](http://ihpgazos.cloudapp.net:9200)", /\*\* @scratch  
> /configuration/config.js/5 \* \* ==== default\_route \* \* This  
> is the default landing page when you don't specify a dashboard to load. You  
> can specify \* files, scripts or saved dashboards here. For example, if  
> you had saved a dashboard called \* `WebLogs' to elasticsearch you might  
> use: \* \* default\_route: '/dashboard/elasticsearch/WebLogs',  
> _/ default\_route : '/dashboard/file/default.json', /_\* @scratch  
> /configuration/config.js/5 \* \* ==== kibana-int \* \* The  
> default ES index to use for storing Kibana specific object \* such as  
> stored dashboards _/ kibana\_index: "kibana-int", /_\* @scratch  
> /configuration/config.js/5 \* \* ==== panel\_name \* \* An array  
> of panel modules available. Panels will only be loaded when they are  
> defined in the \* dashboard, but this list is used in the "add panel"  
> interface. _/ panel\_names: [ 'histogram', 'map',  
> 'goal', 'table', 'filtering', 'timepicker',  
> 'text', 'hits', 'column', 'trends', 'bettermap',  
> 'query', 'terms', 'stats', 'sparklines' ] });});_
> 
> All suggestions will be valued.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/07ae376d-b6cd-4e53-bab2-bcdf30a565af%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/07ae376d-b6cd-4e53-bab2-bcdf30a565af%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:53am UTC](https://discuss.elastic.co/t/setting-up-packetbeat-elasticsearch-kibana/20436/4 "2017-07-06T00:53:45Z")

</div>


