# Tshark output support

**URL:** <https://discuss.elastic.co/t/tshark-output-support/226372>\
**Category:** Elasticsearch\
**Created:** [April 3, 2020, 9:28am UTC](https://discuss.elastic.co/t/tshark-output-support/226372 "2020-04-03T09:28:17Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [April 3, 2020, 9:28am UTC](https://discuss.elastic.co/t/tshark-output-support/226372/1 "2020-04-03T09:28:17Z")

</div>

Which versions of Tshark json for ES are supported? Looks like old version (v2) is working fine when in new (v3) output didn't get parsed in latest ES (accually why, because it have no sense because this output is dedicated).

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 3, 2020, 1:49pm UTC](https://discuss.elastic.co/t/tshark-output-support/226372/2 "2020-04-03T13:49:01Z")

</div>

Hey,

can you clarify your setup? Are you using packetbeat together with `tshark`? If so, which version?

As Elasticsearch only understands HTTP, you need to explain your tooling around that to prevent confusion and possibly giving wrong hints.

Thanks!

--Alex

---

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [April 3, 2020, 9:07pm UTC](https://discuss.elastic.co/t/tshark-output-support/226372/3 "2020-04-03T21:07:45Z")

</div>

I am using tshark with logstash, as in article [https://www.elastic.co/blog/analyzing-network-packets-with-wireshark-elasticsearch-and-kibana](https://www.elastic.co/blog/analyzing-network-packets-with-wireshark-elasticsearch-and-kibana) it works fine with old tshark version, but not with new one.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 6, 2020, 1:27pm UTC](https://discuss.elastic.co/t/tshark-output-support/226372/4 "2020-04-06T13:27:43Z")

</div>

can you share an exception? And also maybe a few lines of the json dump that tshark has produced?

---

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [April 7, 2020, 12:00pm UTC](https://discuss.elastic.co/t/tshark-output-support/226372/5 "2020-04-07T12:00:00Z")

</div>

When I try upload mapping from tshark3 have error:

```auto
{"error":{"root_cause":[{"type":"parse_exception","reason":"Failed to parse content to map"}],"type":"parse_exception","reason":"Failed to parse content to map","caused_by":{"type":"json_parse_exception","reason":"Duplicate field 'dhcp_dhcp_option_value_uint'\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@4c5d35f8; line: 1, column: 14708]"}},"status":400}

```

and in mapping json I have 3 fields `dhcp_dhcp_option_value_uint`

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 7, 2020, 1:47pm UTC](https://discuss.elastic.co/t/tshark-output-support/226372/6 "2020-04-07T13:47:54Z")

</div>

You may want to read about [coercing](https://www.elastic.co/guide/en/elasticsearch/reference/7.6/coerce.html)

---

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [April 9, 2020, 8:52pm UTC](https://discuss.elastic.co/t/tshark-output-support/226372/7 "2020-04-09T20:52:27Z")

</div>

Can I somehow just update selected field to be IP? Looks like coercing have option like this but I can't find any example to exacly do this. Also when I have my field name, how use that in such query? What I mean I don't know how it is recessed in json etc - I just know my field name from Kibana.

Also I need setup that on index pattern, because my indexes are generated every day (have date in name). All is generated automatic from reading jsons from tshark. I just want fix IPv4 field (I know name from Kibana) from string to IP, that is all :).

---

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [April 13, 2020, 2:15pm UTC](https://discuss.elastic.co/t/tshark-output-support/226372/8 "2020-04-13T14:15:12Z")

</div>

Additionaly tshark mapping isn't good, because when I want filter by some protocols, it just dosent always works.

For example there is mdns in wireshark as filter, there is protocol with such name, there are fields in kibana from tshark etc... but when I do:

`tshark -G elastic-mapping --elastic-mapping-filter mdns`

```auto
{
  "index_patterns": "packets-*",
  "settings": {
    "index.mapping.total_fields.limit": 1000000
  },
  "mappings": {
    "doc": {
      "dynamic": false,
      "properties": {
        "timestamp": {
          "type": "date"
        },
        "layers": {
          "properties": {}
        }
      }
    }
  }
}

```

Just tshark don't have mapping for that protocol, btw it accept anything in `--elastic-mapping-filter` so I really don't know if name is wrong or just there is no info etc.

`--elastic-mapping-filter cyberzlo`

```auto
$ tshark -G elastic-mapping --elastic-mapping-filter cyberzlo
{
  "index_patterns": "packets-*",
  "settings": {
    "index.mapping.total_fields.limit": 1000000
  },
  "mappings": {
    "doc": {
      "dynamic": false,
      "properties": {
        "timestamp": {
          "type": "date"
        },
        "layers": {
          "properties": {}
        }
      }
    }
  }
}

```

But when logstash put pcap in elastic format in elasticsearch, there are many fields - so just mapping export dont work, because packets have many fields…

**So most easy would be update selected fields by names and just parse tchem as IP, like some filter to logstash, which import it and change index name etc. Is this possible?**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2020, 2:15pm UTC](https://discuss.elastic.co/t/tshark-output-support/226372/9 "2020-05-11T14:15:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
