Why my packetbeat capture too much fields?


(shell.b2t) #1

Hi:
my env is packetbeat 5.5.1, in kibana management-index patterns,there is about 3000 fields,like this

http.request.headers.hcxrwnivhh  
http.request.headers.ehzayscxyp  
http.request.headers.cqddzwwqrx  
http.request.headers.qmwszdvxwb

why?


(Mark Walkom) #2

PB just passes through what it gets, have you tried looking at the raw incoming request using wireshark or similar?


(shell.b2t) #3

but These fields do not appear in discover

index patterns fields :

discover fields:


(Tudor Golubenco) #4

I think it's enough for one HTTP response to contain all those headers and then they will be considered as fields in Elasticsearch. Try looking for them with something like this in Kibana: _exists_:http.request.headers.anesfqrwm.

Btw, PB by default doesn't capture any header fields. You probably enabled the send_all_headers option? Perhaps you want to define a whitelist using the include_headers option.


(shell.b2t) #5

Hi,tudor:

thk,i disable send_all_headers after,the problem not exit.


(system) #6

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.