# UDP packets cover 50% of packetbeat logs

**URL:** <https://discuss.elastic.co/t/udp-packets-cover-50-of-packetbeat-logs/272689>\
**Category:** SIEM\
**Created:** [May 11, 2021, 11:52am UTC](https://discuss.elastic.co/t/udp-packets-cover-50-of-packetbeat-logs/272689 "2021-05-11T11:52:48Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ethical20](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethical20/32/68123_2.png) [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Post date:** [May 11, 2021, 11:52am UTC](https://discuss.elastic.co/t/udp-packets-cover-50-of-packetbeat-logs/272689/1 "2021-05-11T11:52:48Z")

</div>

Hi,

I can see that 50% of my packetbeat logs are from `network.transport: udp` .

In terms of SIEM perspective do I need this types of logs in kibana? (I don't use any VOIP or streaming services on my monitored machine.)

Any help is really appreciated.

Thank you!

---

<div class="post-metadata">

**Author:** ![AngelaChuang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angelachuang/32/49719_2.png) [@AngelaChuang](https://discuss.elastic.co/u/AngelaChuang)\
**Post date:** [May 11, 2021, 2:58pm UTC](https://discuss.elastic.co/t/udp-packets-cover-50-of-packetbeat-logs/272689/2 "2021-05-11T14:58:57Z")

</div>

Hello @ethical20 ,

Would like to know where do you usually browse you logs in? I think it would be easier if you filter it out in Kibana.

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [May 12, 2021, 1:27am UTC](https://discuss.elastic.co/t/udp-packets-cover-50-of-packetbeat-logs/272689/3 "2021-05-12T01:27:06Z")

</div>

> [@ethical20](#):
>
> I can see that 50% of my packetbeat logs are from `network.transport: udp` .
> 
> In terms of SIEM perspective do I need this types of logs in kibana? (I don't use any VOIP or streaming services on my monitored machine.)
> 
> Any help is really appreciated.
> 
> Thank you!

You can drop specific information before Elasticsearch ingest it by using [Ingest Pipelines](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html)

But as a SOC Engineer myself, I would recommend against it.

Can you show an example of the packetbeat logs?

---

<div class="post-metadata">

**Author:** ![ethical20](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethical20/32/68123_2.png) [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Post date:** [May 12, 2021, 7:49am UTC](https://discuss.elastic.co/t/udp-packets-cover-50-of-packetbeat-logs/272689/4 "2021-05-12T07:49:52Z")

</div>

Hi @AngelaChuang

I browse logs using kibana, I know i can filter them there but at the end I'm having a very large number of them (which means higher storage space needed and processing resources).

My question is: From a security perspective are upd packets important or not and how? (if Im not using streaming / gaming / voip services)

Thanks you!

---

<div class="post-metadata">

**Author:** ![ethical20](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethical20/32/68123_2.png) [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Post date:** [May 12, 2021, 8:11am UTC](https://discuss.elastic.co/t/udp-packets-cover-50-of-packetbeat-logs/272689/5 "2021-05-12T08:11:12Z")

</div>

Hi @austinsonger

I can drop them by using processors from packetbeat.yml

But you said ` "as a SOC Engineer myself, I would recommend against it"`

Can you please say why? I mean what can a security analyst benefit from upd traffic if the server doesn't use (streaming / gaming / voip services).

Isn't udp meant for 'internal ping flows'? Or I'm missing the importance/definition of udp? If yes I would appreciate sharing some resources about threat hunting via upd logs.

Thanks!

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [May 12, 2021, 6:21pm UTC](https://discuss.elastic.co/t/udp-packets-cover-50-of-packetbeat-logs/272689/6 "2021-05-12T18:21:41Z")

</div>

Just think about the services (`DNS`, `DHCP`, and others) that use UDP.

Now you may be able to drop UDP packets if the packets are below a specific number and only accept UDP packets if it goes above that level.

---

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [May 13, 2021, 4:25pm UTC](https://discuss.elastic.co/t/udp-packets-cover-50-of-packetbeat-logs/272689/7 "2021-05-13T16:25:09Z")

</div>

packetbeat has a bpf filter, ive only briefly used packetbeat but i spent a fair amount of time with BRO.

If you need to filter traffic to get rid of the noise then you will need to analyse the traffic and look to add filters, ideally based on source, destination, port and protocol. You might find that there is alot of broadcast traffic on the network for example.

UDP is useful, for example DNS traditionally is sent over UDP, this data is valuable from an activity perspecive, trying to spot C&C, DNS tunneling etc

---

<div class="post-metadata">

**Author:** ![ethical20](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethical20/32/68123_2.png) [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Post date:** [May 18, 2021, 8:34am UTC](https://discuss.elastic.co/t/udp-packets-cover-50-of-packetbeat-logs/272689/8 "2021-05-18T08:34:24Z")

</div>

Perfect.. thanks @probson and to all the people who helped in this @austinsonger.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2021, 8:35am UTC](https://discuss.elastic.co/t/udp-packets-cover-50-of-packetbeat-logs/272689/9 "2021-06-15T08:35:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
