# TShark and Rotating JSON Files

**URL:** <https://discuss.elastic.co/t/tshark-and-rotating-json-files/195124>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 14, 2019, 2:08am UTC](https://discuss.elastic.co/t/tshark-and-rotating-json-files/195124 "2019-08-14T02:08:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![michaelberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaelberg/32/51063_2.png) [@michaelberg](https://discuss.elastic.co/u/michaelberg)\
**Post date:** [August 14, 2019, 2:08am UTC](https://discuss.elastic.co/t/tshark-and-rotating-json-files/195124/1 "2019-08-14T02:08:01Z")

</div>

Greetings ...

I am searching and searching and cannot seem to find a way to have TShark capture packets live to ElasticSearch JSON format and rotate them so I create a new JSON file, say, every hour or every 6 hours or whatever ...

Otherwise it seems that the TShark JSON output just grows and grows and grows until you run out of Disk space ...

If I could capture the JSON file and rotate it I could delete the ElasticSearch JSON files that have already been ingested or I could archive them or whatever ....

I've got the ElasticSearch Index created ... have the Ingest Pipeline created to rename fields and do GeoIP lookups ... the works ... and I've tested it manually from the console and it works like a charm!

Now I just need to feed the JSON file into Elastic Cloud using Filebeat and I'm off to the races!

Thanks in advance for any tips people can send my way!

Cheers!

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 14, 2019, 9:50am UTC](https://discuss.elastic.co/t/tshark-and-rotating-json-files/195124/2 "2019-08-14T09:50:11Z")

</div>

This is more a tshark questions. Never tried myself, but have you tried with the `-b` flag?

```auto
$ tshark -h
...
Capture output:
  -b <ringbuffer opt.> ... duration:NUM - switch to next file after NUM secs
                           filesize:NUM - switch to next file after NUM KB
                              files:NUM - ringbuffer: replace after NUM files
...

```

---

<div class="post-metadata">

**Author:** ![michaelberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaelberg/32/51063_2.png) [@michaelberg](https://discuss.elastic.co/u/michaelberg)\
**Post date:** [August 14, 2019, 4:24pm UTC](https://discuss.elastic.co/t/tshark-and-rotating-json-files/195124/3 "2019-08-14T16:24:44Z")

</div>

Steffens ...

Thanks kindly for the reply ....

Absolutely ... it's purely a TShark question ... but since it has direct ties into ElasticSearch and because it's reference **[HERE](https://www.elastic.co/blog/analyzing-network-packets-with-wireshark-elasticsearch-and-kibana)** I figured I'd post the question here in the off chance someone else has experienced this ...

If you try and run TShark with the -b option while outputting to JSON you get the attached error ..

![55%20AM](https://us1.discourse-cdn.com/elastic/original/3X/3/4/34f7c30ce541ceba4d178007457a2f84b3ce43a0.png)

If you try running the commands like the attached example it will properly rotate the PCAPs but the JSON file just keeps growing and growing ... the 2nd try in the attached didn't embed the date on the JSON but the JSON just kept growing as well ..

 ![38%20AM](https://us1.discourse-cdn.com/elastic/original/3X/7/4/74f910bde78069888ee7c00cb23ba74b5d7fd9f6.png)

There's gotta be a way to rotate the JSON ... I'll keep searching but if someone has a great idea I'm all ears ... I suppose we could write a CRON job of some sort to try and do the rotation but with that file filling up as quickly as it does I could a CRON job solution being fraught with issues ...

Thanks all ... cheers!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 11, 2019, 4:24pm UTC](https://discuss.elastic.co/t/tshark-and-rotating-json-files/195124/4 "2019-09-11T16:24:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
