# Using packetbeat with pf\_ring

**URL:** <https://discuss.elastic.co/t/using-packetbeat-with-pf-ring/243925>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [August 5, 2020, 7:58pm UTC](https://discuss.elastic.co/t/using-packetbeat-with-pf-ring/243925 "2020-08-05T19:58:59Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![luciferdude](https://avatars.discourse-cdn.com/v4/letter/l/f19dbf/32.png) [@luciferdude](https://discuss.elastic.co/u/luciferdude)\
**Post date:** [August 5, 2020, 7:58pm UTC](https://discuss.elastic.co/t/using-packetbeat-with-pf-ring/243925/1 "2020-08-05T19:58:59Z")

</div>

Hello,

Testing packetbeat with af\_packet and pcap. getting an error when testing with pf\_ring. I have 10 GB NIC and trying to capture DNS traffic over that nic.

`ERROR	instance/beat.go:906	Exiting: Unknown sniffer type: pf_ring`

I've installed pfring-7.4.0-2736.x86\_64.rpm; pfring-dkms-7.4.0-2700.noarch.rpm and dependency packages. I've added the mgmt interface and capture\_interfaces in the interfaces.conf. Can someone please help me?

- packetbeat.interfaces.device: 0
- packetbeat.interfaces.type: pf\_ring
- packetbeat.interfaces.snaplen: 65535
- packetbeat.ignore\_outgoing: true

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 2, 2020, 9:59pm UTC](https://discuss.elastic.co/t/using-packetbeat-with-pf-ring/243925/2 "2020-09-02T21:59:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
