# \#packetbeat

**URL:** https://discuss.elastic.co/tag/packetbeat/55.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [AbuseCH integration issue](https://discuss.elastic.co/t/abusech-integration-issue/385076)

<div class="topic-metadata">

**Author:** [@maryam\_naeem](https://discuss.elastic.co/u/maryam_naeem)\
**Replies:** 3\
**Last updated:** [February 17, 2026, 4:29pm UTC](https://discuss.elastic.co/t/abusech-integration-issue/385076 "2026-02-17T16:29:52Z")

</div>

I am using elastic basic plan , but i have a problem being encountered whenever i integrate abusech integration v1.25.0 , i cant see any datastream or data indices , which means the data is not flowing , when i researc…

---

## [Panic: runtime error: makeslice: cap out of range](https://discuss.elastic.co/t/panic-runtime-error-makeslice-cap-out-of-range/384887)

<div class="topic-metadata">

**Author:** [@whanklee](https://discuss.elastic.co/u/whanklee)\
**Replies:** 0\
**Last updated:** [February 3, 2026, 2:00pm UTC](https://discuss.elastic.co/t/panic-runtime-error-makeslice-cap-out-of-range/384887 "2026-02-03T14:00:55Z")

</div>

Packetbeat 9.3.0 crashes with Go panic in DHCPv4 parser (makeslice: cap out of range) on Ubuntu 24 Environment • OS: Ubuntu Server 24.04 LTS (amd64) • Packetbeat version: packetbeat version 9.3.0 (amd64) libbeat 9…

---

## [Struggling to set up multiple namespaces for a single Beats data stream](https://discuss.elastic.co/t/struggling-to-set-up-multiple-namespaces-for-a-single-beats-data-stream/383212)

<div class="topic-metadata">

**Author:** [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Replies:** 2\
**Last updated:** [November 4, 2025, 4:27pm UTC](https://discuss.elastic.co/t/struggling-to-set-up-multiple-namespaces-for-a-single-beats-data-stream/383212 "2025-11-04T16:27:54Z")

</div>

Dear community In Elastic Fleet you can set a namespace for an integration so you can have multiple data streams for a single type of index template without having to duplicate settings (ILM policy, index template, comp…

---

## [JA4 on Packetbeat?](https://discuss.elastic.co/t/ja4-on-packetbeat/381444)

<div class="topic-metadata">

**Author:** [@Victor\_Monteagudo](https://discuss.elastic.co/u/Victor_Monteagudo)\
**Replies:** 0\
**Last updated:** [August 29, 2025, 10:01am UTC](https://discuss.elastic.co/t/ja4-on-packetbeat/381444 "2025-08-29T10:01:40Z")

</div>

Hello, Are there any plans to implement hashes JA4, JA4+ on the decoder TLS of Packetbeat? Thank you

---

## [How to Use Machine Learning with Packetbeat to Detect Network Anomalies in Elastic Stack?](https://discuss.elastic.co/t/how-to-use-machine-learning-with-packetbeat-to-detect-network-anomalies-in-elastic-stack/378075)

<div class="topic-metadata">

**Author:** [@nzeland149](https://discuss.elastic.co/u/nzeland149)\
**Replies:** 0\
**Last updated:** [May 13, 2025, 9:31am UTC](https://discuss.elastic.co/t/how-to-use-machine-learning-with-packetbeat-to-detect-network-anomalies-in-elastic-stack/378075 "2025-05-13T09:31:07Z")

</div>

I'm currently working on a network monitoring project using the Elastic Stack and Packetbeat, and I'm interested in using Elastic Machine Learning to detect anomalies in network traffic. However, I'm not sure how to prop…

---

## [Packetbeat cant capt http and dns](https://discuss.elastic.co/t/packetbeat-cant-capt-http-and-dns/376412)

<div class="topic-metadata">

**Author:** [@nzeland149](https://discuss.elastic.co/u/nzeland149)\
**Replies:** 3\
**Last updated:** [April 2, 2025, 3:13pm UTC](https://discuss.elastic.co/t/packetbeat-cant-capt-http-and-dns/376412 "2025-04-02T15:13:41Z")

</div>

hi i have configured port mirriong in my network to a second interface in my packetbeat machine to send logs to elastic it sends networkflows but i cant see http transaction or dns where should be the probelem (mayber …

---

## [Elastic GeoIP does not work for Linux hosts](https://discuss.elastic.co/t/elastic-geoip-does-not-work-for-linux-hosts/373987)

<div class="topic-metadata">

**Author:** [@maof97](https://discuss.elastic.co/u/maof97)\
**Replies:** 3\
**Last updated:** [April 1, 2025, 4:20pm UTC](https://discuss.elastic.co/t/elastic-geoip-does-not-work-for-linux-hosts/373987 "2025-04-01T16:20:42Z")

</div>

Hello, I have a rather strange problem. My fleet agents that are either Windows or MacOS will send the network flows just fine, including geoid enrichment: Example: But the flows send by Linux hosts do not contain …

---

## [Packetbeat with Ai, helpme please](https://discuss.elastic.co/t/packetbeat-with-ai-helpme-please/376318)

<div class="topic-metadata">

**Author:** [@nzeland149](https://discuss.elastic.co/u/nzeland149)\
**Replies:** 4\
**Last updated:** [March 25, 2025, 9:49am UTC](https://discuss.elastic.co/t/packetbeat-with-ai-helpme-please/376318 "2025-03-25T09:49:47Z")

</div>

i have a question i want to set output file of packetbeat in a file and i want this file get analysed by ai and detect anomalies and then send it to wazuh(works wih filebeat) to view it in kibana can anyone help me or t…

---

## [Disable system metrics on packetbeat](https://discuss.elastic.co/t/disable-system-metrics-on-packetbeat/373281)

<div class="topic-metadata">

**Author:** [@fcecagno](https://discuss.elastic.co/u/fcecagno)\
**Replies:** 0\
**Last updated:** [January 16, 2025, 2:29pm UTC](https://discuss.elastic.co/t/disable-system-metrics-on-packetbeat/373281 "2025-01-16T14:29:57Z")

</div>

Hi, I'm running packetbeat and I'm not interested in the system metrics reported by it - I use a different method to monitoring the host. Because I didn't add the SYS\_PTRACE capability to the docker container, I keep rec…

---

## [Elastic agent 8.15.4 and 3 not installing wpcap/npcap.dll](https://discuss.elastic.co/t/elastic-agent-8-15-4-and-3-not-installing-wpcap-npcap-dll/370854)

<div class="topic-metadata">

**Author:** [@DJMogens](https://discuss.elastic.co/u/DJMogens)\
**Replies:** 2\
**Last updated:** [December 1, 2024, 8:32pm UTC](https://discuss.elastic.co/t/elastic-agent-8-15-4-and-3-not-installing-wpcap-npcap-dll/370854 "2024-12-01T20:32:00Z")

</div>

Just tried to upgrade my lab to elastic 8.15.4 and the elastic-agent doesn't install the wpcap.dll automatically. I had to manually install npcap to get packetbeat to start on the agents (via the network packet inspectio…

---

## [What is the hardware requirement for packetbeat?](https://discuss.elastic.co/t/what-is-the-hardware-requirement-for-packetbeat/369045)

<div class="topic-metadata">

**Author:** [@yumeko](https://discuss.elastic.co/u/yumeko)\
**Replies:** 0\
**Last updated:** [October 18, 2024, 7:47am UTC](https://discuss.elastic.co/t/what-is-the-hardware-requirement-for-packetbeat/369045 "2024-10-18T07:47:58Z")

</div>

Hello, We currently have a DNS server with the following specifications: CPU: 3 vCPU RAM: 3 GB Disk: 110 GB We plan to install Packetbeat to monitor traffic on port 53. The average traffic volume on this port is aro…

---

## [Pipeline not created during setup of packetbeat 8.15.1 on windows](https://discuss.elastic.co/t/pipeline-not-created-during-setup-of-packetbeat-8-15-1-on-windows/366656)

<div class="topic-metadata">

**Author:** [@drops](https://discuss.elastic.co/u/drops)\
**Replies:** 4\
**Last updated:** [October 15, 2024, 5:50pm UTC](https://discuss.elastic.co/t/pipeline-not-created-during-setup-of-packetbeat-8-15-1-on-windows/366656 "2024-10-15T17:50:32Z")

</div>

{"log.level":"warn","@timestamp":"2024-09-17T09:27:50.421+0200","log.logger":"elasticsearch","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.(Client).applyItemStatus","file.name":"elas…

---

## [Pipeline with id \[packetbeat-8.15.2-routing\] does not exist, dropping event!](https://discuss.elastic.co/t/pipeline-with-id-packetbeat-8-15-2-routing-does-not-exist-dropping-event/368135)

<div class="topic-metadata">

**Author:** [@jimB100](https://discuss.elastic.co/u/jimB100)\
**Replies:** 11\
**Last updated:** [October 4, 2024, 1:14pm UTC](https://discuss.elastic.co/t/pipeline-with-id-packetbeat-8-15-2-routing-does-not-exist-dropping-event/368135 "2024-10-04T13:14:34Z")

</div>

Hi, I'm testing out packetbeat to ship dns data to our self-hosted elastic server, I have tried version x64 windows 8.15.2 and 8.15.0 and neither version created the routing pipeline {"log.level":"warn","@timestamp":"20…

---

## [Network Packet Capture/Packetbeat](https://discuss.elastic.co/t/network-packet-capture-packetbeat/364423)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [August 5, 2024, 9:58pm UTC](https://discuss.elastic.co/t/network-packet-capture-packetbeat/364423 "2024-08-05T21:58:58Z")

</div>

Hello, based on the documentation: Network Packet Capture | Documentation (elastic.co) Field network.application appears only in the SIP section, are there plans to add this field to the Flows dataset?

---

## [How to use\`add\_process\_metadata\`in packetbeat to get process.pid?](https://discuss.elastic.co/t/how-to-use-add-process-metadata-in-packetbeat-to-get-process-pid/363217)

<div class="topic-metadata">

**Author:** [@asdfsx](https://discuss.elastic.co/u/asdfsx)\
**Replies:** 0\
**Last updated:** [July 16, 2024, 11:57am UTC](https://discuss.elastic.co/t/how-to-use-add-process-metadata-in-packetbeat-to-get-process-pid/363217 "2024-07-16T11:57:23Z")

</div>

I start my packetbeat by docker-compose, and tring to use add\_process\_metadata to add process.pid to the packet data. But I failed, the process.pid is always empty. I use following docker-compose to start the packetbeat …

---

## [Cannot write to a field alias \[agent.hostname\]](https://discuss.elastic.co/t/cannot-write-to-a-field-alias-agent-hostname/362019)

<div class="topic-metadata">

**Author:** [@bhagt](https://discuss.elastic.co/u/bhagt)\
**Replies:** 1\
**Last updated:** [June 25, 2024, 11:44am UTC](https://discuss.elastic.co/t/cannot-write-to-a-field-alias-agent-hostname/362019 "2024-06-25T11:44:29Z")

</div>

Hi, I encounter the following error during installation of packetbeat: {"type":"mapper\_parsing\_exception","reason":"failed to parse","caused\_by":{"type":"illegal\_argument\_exception","reason":"Cannot write to a field al…

---

## [How to monitor udp protocol (new protocol)](https://discuss.elastic.co/t/how-to-monitor-udp-protocol-new-protocol/359184)

<div class="topic-metadata">

**Author:** [@Alisher\_Nabiev](https://discuss.elastic.co/u/Alisher_Nabiev)\
**Replies:** 1\
**Last updated:** [May 9, 2024, 2:00pm UTC](https://discuss.elastic.co/t/how-to-monitor-udp-protocol-new-protocol/359184 "2024-05-09T14:00:31Z")

</div>

hi, i need to sniff traffic from udp custom port. i tried this conf but no success: " - type: udp include\_fields: \["total\_length", "protocol", "source.ip", "destination.ip", "source.port", "destination.port"\] incl…

---

## [Vxlan protocol capturing](https://discuss.elastic.co/t/vxlan-protocol-capturing/359156)

<div class="topic-metadata">

**Author:** [@Alisher\_Nabiev](https://discuss.elastic.co/u/Alisher_Nabiev)\
**Replies:** 0\
**Last updated:** [May 9, 2024, 9:09am UTC](https://discuss.elastic.co/t/vxlan-protocol-capturing/359156 "2024-05-09T09:09:06Z")

</div>

Hi, I need to capture VXLAN protocol from my EC2 interface. I am trying to perform port mirroring in AWS, but based on the logs, it seems that VXLAN is not being recognized. The error message I am receiving is: "2024-05-…

---

## [PacketBeat sometimes do not match the http.request with http.response](https://discuss.elastic.co/t/packetbeat-sometimes-do-not-match-the-http-request-with-http-response/358674)

<div class="topic-metadata">

**Author:** [@ccastro](https://discuss.elastic.co/u/ccastro)\
**Replies:** 1\
**Last updated:** [May 3, 2024, 6:23pm UTC](https://discuss.elastic.co/t/packetbeat-sometimes-do-not-match-the-http-request-with-http-response/358674 "2024-05-03T18:23:44Z")

</div>

Using packetbeat-8.13.2-linux-x86\_64 found that sometimes http.request do not match with the real http.response.body. The response.body belongs to another request. Try change to period: -1s and use pcap instead af\_packe…

---

## [Packetbeat error connecting to elasticsearch](https://discuss.elastic.co/t/packetbeat-error-connecting-to-elasticsearch/356545)

<div class="topic-metadata">

**Author:** [@Syphax](https://discuss.elastic.co/u/Syphax)\
**Replies:** 3\
**Last updated:** [April 2, 2024, 11:12am UTC](https://discuss.elastic.co/t/packetbeat-error-connecting-to-elasticsearch/356545 "2024-04-02T11:12:10Z")

</div>

hi everyone, my elasticsearch server receives IPs dynamically from a DHCP server. my elastic server had an address of 192.168.100.116 when I installed it, the next day the address was changed to 192.168.100.126 and when…

---

## [\[mysql\]queries cannot be logged](https://discuss.elastic.co/t/mysql-queries-cannot-be-logged/354087)

<div class="topic-metadata">

**Author:** [@h32309](https://discuss.elastic.co/u/h32309)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 6:55am UTC](https://discuss.elastic.co/t/mysql-queries-cannot-be-logged/354087 "2024-02-26T06:55:52Z")

</div>

When the query field contains a type of DOUBLE, the query cannot be logged.

---

## [Packetbeat mysql only works if metricbeat mysql enabled?](https://discuss.elastic.co/t/packetbeat-mysql-only-works-if-metricbeat-mysql-enabled/352113)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [January 31, 2024, 9:37pm UTC](https://discuss.elastic.co/t/packetbeat-mysql-only-works-if-metricbeat-mysql-enabled/352113 "2024-01-31T21:37:05Z")

</div>

My goal is to go to Kibana \> Dashboard \> \[Packetbeat\] MySQL performance ECS and see some visualizations of my mysql performance. I find that \[Packetbeat\] MySQL performance only shows a bunch of No results found widgets.…

---

## [Packetbeat 7.x not working on Windows](https://discuss.elastic.co/t/packetbeat-7-x-not-working-on-windows/351533)

<div class="topic-metadata">

**Author:** [@eagle840](https://discuss.elastic.co/u/eagle840)\
**Replies:** 7\
**Last updated:** [January 26, 2024, 1:58pm UTC](https://discuss.elastic.co/t/packetbeat-7-x-not-working-on-windows/351533 "2024-01-26T13:58:13Z")

</div>

Any version of packetbeat.exe version 7.x on windows returns nothing. eg: user\> packetbeat -v user \> The same effect is seen in powershell and cmdline, and reproduced the effect on different machines. However remov…

---

## [I have a question about packetbeat character encoding](https://discuss.elastic.co/t/i-have-a-question-about-packetbeat-character-encoding/350637)

<div class="topic-metadata">

**Author:** [@67PNV5pp1gS6q53B](https://discuss.elastic.co/u/67PNV5pp1gS6q53B)\
**Replies:** 5\
**Last updated:** [January 10, 2024, 3:50pm UTC](https://discuss.elastic.co/t/i-have-a-question-about-packetbeat-character-encoding/350637 "2024-01-10T15:50:31Z")

</div>

I want to capture the request and return of the http port, but the data returned by http contains Chinese characters and uses GBK encoding. Garbled characters appear after packetbeat is sent to elastic. I did not find th…

---

## [Adding support for new protocols under packetbeat](https://discuss.elastic.co/t/adding-support-for-new-protocols-under-packetbeat/350425)

<div class="topic-metadata">

**Author:** [@ACodingfreak](https://discuss.elastic.co/u/ACodingfreak)\
**Replies:** 2\
**Last updated:** [January 6, 2024, 12:38am UTC](https://discuss.elastic.co/t/adding-support-for-new-protocols-under-packetbeat/350425 "2024-01-06T00:38:31Z")

</div>

Hi All, I do have couple of questions with respect to packetbeat and need your help in understanding the same Is there any updated article or document in adding support for new protocols in packetbeat? Did anyone …

---

## [GeoIP enrich IP addresses broken if fileting with include\_fields](https://discuss.elastic.co/t/geoip-enrich-ip-addresses-broken-if-fileting-with-include-fields/346824)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 1\
**Last updated:** [November 10, 2023, 10:50pm UTC](https://discuss.elastic.co/t/geoip-enrich-ip-addresses-broken-if-fileting-with-include-fields/346824 "2023-11-10T22:50:23Z")

</div>

I'm logging DNS packets without dns.response\_code: NOERROR. This part works fine. But when I try to smile down the logged data, by adding a filter to drop all but some selected fields, GeoIP breaks. GeoIP can't be used …

---

## [Warn nfs/rpc.go - multifragment rpc message in logs](https://discuss.elastic.co/t/warn-nfs-rpc-go-multifragment-rpc-message-in-logs/346743)

<div class="topic-metadata">

**Author:** [@tomaskcz](https://discuss.elastic.co/u/tomaskcz)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 8:38pm UTC](https://discuss.elastic.co/t/warn-nfs-rpc-go-multifragment-rpc-message-in-logs/346743 "2023-11-08T20:38:17Z")

</div>

I am getting lots of logs messages for packebeat with {"log.level":"warn","@timestamp":"2023-11-08T20:27:29.998Z","log.origin":{"file.name":"nfs/rpc.go","file.line":227},"message":"multifragment rpc message","service.na…

---

## [\[Packetbeat\] packet loss for mysql queries](https://discuss.elastic.co/t/packetbeat-packet-loss-for-mysql-queries/345857)

<div class="topic-metadata">

**Author:** [@lenovore](https://discuss.elastic.co/u/lenovore)\
**Replies:** 2\
**Last updated:** [October 30, 2023, 2:23am UTC](https://discuss.elastic.co/t/packetbeat-packet-loss-for-mysql-queries/345857 "2023-10-30T02:23:21Z")

</div>

Version: packetbeat-8.10.4、packetbeat-7.10.2 Operating System: ubuntu20.04 #18471 #20890 Three years have passed, and the problem of packet loss in MySQL queries remains unresolved. sql: use dba\_backup; select \* fr…

---

## [Packetbeat's tls report has not bytes\_out field](https://discuss.elastic.co/t/packetbeats-tls-report-has-not-bytes-out-field/344145)

<div class="topic-metadata">

**Author:** [@hansc](https://discuss.elastic.co/u/hansc)\
**Replies:** 0\
**Last updated:** [September 29, 2023, 3:28pm UTC](https://discuss.elastic.co/t/packetbeats-tls-report-has-not-bytes-out-field/344145 "2023-09-29T15:28:56Z")

</div>

I have packetbeat 8.10.2 installed in Debian 11. The protocols configurations are - type: http ports: \[80, 8080, 8000, 18083\] - type: tls ports: - 443 # HTTPS I am successfully see the bytes\_in and bytes\_o…

---

## [Packetbeat MongoDB in Windows Server doesn't work](https://discuss.elastic.co/t/packetbeat-mongodb-in-windows-server-doesnt-work/343903)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 2:53pm UTC](https://discuss.elastic.co/t/packetbeat-mongodb-in-windows-server-doesnt-work/343903 "2023-09-26T14:53:30Z")

</div>

Hi I'm trying to monitor mongodb connections using packetbeat, doing it locally on my mongodb works fine: this is my configuration: packetbeat.interfaces: - device: \\Device\\NPF\_{422A5385-8A2F-46AB-8B71-2C94764B14FA} …

[Next page](https://discuss.elastic.co/tag/packetbeat/55.md?match_all_tags=true&page=1&tags%5B%5D=packetbeat)
