# Using packetbeat with macos/ios remote virutal interface

**URL:** <https://discuss.elastic.co/t/using-packetbeat-with-macos-ios-remote-virutal-interface/183604>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [May 30, 2019, 8:15pm UTC](https://discuss.elastic.co/t/using-packetbeat-with-macos-ios-remote-virutal-interface/183604 "2019-05-30T20:15:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![stru](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@stru](https://discuss.elastic.co/u/stru)\
**Post date:** [May 30, 2019, 8:15pm UTC](https://discuss.elastic.co/t/using-packetbeat-with-macos-ios-remote-virutal-interface/183604/1 "2019-05-30T20:15:02Z")

</div>

Does packetbeat support use of the remote virtual interface on macOS? If so, what needs to be done to get it to work correctly.

I am getting this error when trying to run packetbeat with rvi0 as an interface in packetbeat.yml:  
Exiting: Sniffer main loop failed: Unsupported link type: UnknownLinkType(12)

---

<div class="post-metadata">

**Author:** ![Michael\_Madden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_madden/32/46640_2.png) [@Michael\_Madden](https://discuss.elastic.co/u/Michael_Madden)\
**Post date:** [June 26, 2019, 8:12pm UTC](https://discuss.elastic.co/t/using-packetbeat-with-macos-ios-remote-virutal-interface/183604/2 "2019-06-26T20:12:57Z")

</div>

Hello, thanks for reaching out about packetbeat devices? Does the `rvi0` interface show up in the output of `packetbeat devices`?

The output should be similar to this:

```auto
1: awdl0 (No description available)
2: bridge0 (No description available)
3: fw0 (No description available)
4: en1 (No description available)
5: en2 (No description available)
6: p2p0 (No description available)
7: en4 (No description available)
8: lo0 (No description available)

```

[https://www.elastic.co/guide/en/beats/packetbeat/current/configuration-interfaces.html#\_sniffing\_configuration\_options](https://www.elastic.co/guide/en/beats/packetbeat/current/configuration-interfaces.html#_sniffing_configuration_options)

---

<div class="post-metadata">

**Author:** ![stru](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@stru](https://discuss.elastic.co/u/stru)\
**Post date:** [June 27, 2019, 6:30pm UTC](https://discuss.elastic.co/t/using-packetbeat-with-macos-ios-remote-virutal-interface/183604/3 "2019-06-27T18:30:17Z")

</div>

Yes rvi0 does appear in the list with (No description available) (Not assigned ip address)

![image001.jpg](https://us1.discourse-cdn.com/elastic/original/3X/f/0/f003192a1f3cbff81737c51a6c1ed5f5dd97394e.jpeg)

---

<div class="post-metadata">

**Author:** ![stru](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@stru](https://discuss.elastic.co/u/stru)\
**Post date:** [July 10, 2019, 7:58pm UTC](https://discuss.elastic.co/t/using-packetbeat-with-macos-ios-remote-virutal-interface/183604/4 "2019-07-10T19:58:45Z")

</div>

Any updates on this issue?  
I'm hoping that since the rvi0 interface appears in the list, that this is fixable problem?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 11, 2019, 12:25pm UTC](https://discuss.elastic.co/t/using-packetbeat-with-macos-ios-remote-virutal-interface/183604/5 "2019-07-11T12:25:42Z")

</div>

UnknownLinkType(12) indicates that this device is not supported and that the device type is not known to the libraries used by packetbeat (I didn't find what type 12 stands for on darwin). Which means that packetbeat does not know about the packet layout and therefore can not parse it.

---

<div class="post-metadata">

**Author:** ![stru](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@stru](https://discuss.elastic.co/u/stru)\
**Post date:** [July 22, 2019, 4:37pm UTC](https://discuss.elastic.co/t/using-packetbeat-with-macos-ios-remote-virutal-interface/183604/6 "2019-07-22T16:37:02Z")

</div>

is it possible to update the libraries or supplement them so that packetbeat can parse? tcpdump and wireshark both are able to parse packets from a remote virtual interface

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2019, 4:37pm UTC](https://discuss.elastic.co/t/using-packetbeat-with-macos-ios-remote-virutal-interface/183604/7 "2019-08-19T16:37:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
