# TCP/UDP configuration question

**URL:** <https://discuss.elastic.co/t/tcp-udp-configuration-question/34445>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [November 12, 2015, 5:20pm UTC](https://discuss.elastic.co/t/tcp-udp-configuration-question/34445 "2015-11-12T17:20:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![uvmvball](https://avatars.discourse-cdn.com/v4/letter/u/8491ac/32.png) [@uvmvball](https://discuss.elastic.co/u/uvmvball)\
**Post date:** [November 12, 2015, 5:20pm UTC](https://discuss.elastic.co/t/tcp-udp-configuration-question/34445/1 "2015-11-12T17:20:33Z")

</div>

I'm new to the packetbeat world and have installed beta3 (will get to the rc1 shortly), but am trying to enable the TCP/UDP protocol and can't seem to figure out where to enable that to see info to send to elastic. I've confirmed UDP packets coming into the box (SNMP traps in this case on port 162) where we've configured it and I thought it might be in the packetbeat.yml file that we'd enable that, but I didn't see any reference to TCP/UDP to watch specific ports.

I even tried adding some references in there to see if that might make any difference, but I don't see anything new:

udp:  
ports: [161, 162]

tcp:  
ports: [162, 22, 23, 115]

I also have MySQL on there and that side is working fine: I see them via Kibana UI accordingly.

Is there anything else that I'm missing?

Thanks.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 12, 2015, 8:24pm UTC](https://discuss.elastic.co/t/tcp-udp-configuration-question/34445/2 "2015-11-12T20:24:50Z")

</div>

Hi @uvmvball,

Packetbeat currently supports the protocols listed here: [https://www.elastic.co/guide/en/beats/packetbeat/current/\_overview.html](https://www.elastic.co/guide/en/beats/packetbeat/current/_overview.html)

SNMP is not one of them, but Logstash has support for SNMP traps: [https://www.elastic.co/guide/en/logstash/current/plugins-inputs-snmptrap.html](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-snmptrap.html)

---

<div class="post-metadata">

**Author:** ![uvmvball](https://avatars.discourse-cdn.com/v4/letter/u/8491ac/32.png) [@uvmvball](https://discuss.elastic.co/u/uvmvball)\
**Post date:** [November 13, 2015, 1:23pm UTC](https://discuss.elastic.co/t/tcp-udp-configuration-question/34445/3 "2015-11-13T13:23:15Z")

</div>

My real question was how to enable the new UDP/TCP protos as I can’t seem to get that working in order to produce any results. I was just using SNMP as example UDP traffic that is coming in.

Sorry for the confusion!

Brad

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 13, 2015, 1:43pm UTC](https://discuss.elastic.co/t/tcp-udp-configuration-question/34445/4 "2015-11-13T13:43:58Z")

</div>

packetbeat works on application layer. It will process TCP/UDP packets by default and (depending on port numbers) forward traffic to application layer analyzers. Unfortunately Packetbeat does not yet publish any stats on IP, TCP or UDP layer. Feel free to add an enhancement request (or Pull request) to [packetbeat](https://github.com/elastic/packetbeat).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:58pm UTC](https://discuss.elastic.co/t/tcp-udp-configuration-question/34445/5 "2017-07-05T21:58:13Z")

</div>


