# Why my packetbeat capture too much fields?

**URL:** <https://discuss.elastic.co/t/why-my-packetbeat-capture-too-much-fields/70017>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [December 26, 2016, 5:32pm UTC](https://discuss.elastic.co/t/why-my-packetbeat-capture-too-much-fields/70017 "2016-12-26T17:32:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![shell.b2t](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@shell.b2t](https://discuss.elastic.co/u/shell.b2t)\
**Post date:** [December 26, 2016, 5:32pm UTC](https://discuss.elastic.co/t/why-my-packetbeat-capture-too-much-fields/70017/1 "2016-12-26T17:32:03Z")

</div>

Hi:  
my env is packetbeat 5.5.1, in kibana management-index patterns,there is about 3000 fields,like this

```
http.request.headers.hcxrwnivhh  
http.request.headers.ehzayscxyp  
http.request.headers.cqddzwwqrx  
http.request.headers.qmwszdvxwb

```

why?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 26, 2016, 10:45pm UTC](https://discuss.elastic.co/t/why-my-packetbeat-capture-too-much-fields/70017/2 "2016-12-26T22:45:49Z")

</div>

PB just passes through what it gets, have you tried looking at the raw incoming request using wireshark or similar?

---

<div class="post-metadata">

**Author:** ![shell.b2t](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@shell.b2t](https://discuss.elastic.co/u/shell.b2t)\
**Post date:** [December 27, 2016, 5:18am UTC](https://discuss.elastic.co/t/why-my-packetbeat-capture-too-much-fields/70017/3 "2016-12-27T05:18:57Z")

</div>

but These fields do not appear in discover

index patterns fields :

![](https://us1.discourse-cdn.com/elastic/original/2X/0/0d356f9a45c52a7b3e9c3c435088029599b42682.png)

discover fields:

![](https://us1.discourse-cdn.com/elastic/original/2X/c/c35e3d2aef76a5f565684d398d8856c7fcbcdd50.png)

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [December 27, 2016, 8:38am UTC](https://discuss.elastic.co/t/why-my-packetbeat-capture-too-much-fields/70017/4 "2016-12-27T08:38:07Z")

</div>

I think it's enough for one HTTP response to contain all those headers and then they will be considered as fields in Elasticsearch. Try looking for them with something like this in Kibana: `_exists_:http.request.headers.anesfqrwm`.

Btw, PB by default doesn't capture any header fields. You probably enabled the `send_all_headers` option? Perhaps you want to define a whitelist using the `include_headers` option.

---

<div class="post-metadata">

**Author:** ![shell.b2t](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@shell.b2t](https://discuss.elastic.co/u/shell.b2t)\
**Post date:** [December 27, 2016, 11:45am UTC](https://discuss.elastic.co/t/why-my-packetbeat-capture-too-much-fields/70017/5 "2016-12-27T11:45:45Z")

</div>

Hi,tudor:

thk,i disable `send_all_headers` after,the problem not exit.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 24, 2017, 11:45am UTC](https://discuss.elastic.co/t/why-my-packetbeat-capture-too-much-fields/70017/6 "2017-01-24T11:45:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
