Beats packetbeat

Elastic · Elastic.Packetbeat

Monitors the network and applications by sniffing packets

Packetbeat is an open source network packet analyzer that ships the data to Elasticsearch. Think of it like a distributed real-time Wireshark with a lot more analytics features. The Packetbeat shippers sniff the traffic between your application processes, parse on the fly protocols like HTTP, MySQL, PostgreSQL, Redis or Thrift and correlate the messages into transactions. For each transaction, the shipper inserts a JSON document into Elasticsearch, where it is stored and indexed. You can then use Kibana to view key metrics and do ad-hoc queries against the data.

winget install --id Elastic.Packetbeat --exact --source winget

Latest 9.3.3

Release Notes

Features and enhancements All

  • Update OTel Collector components to v0.148.0. #49578 Filebeat
  • Add retry back-off logic to streaming input CrowdStrike follower. #48542 #46072
  • Add secret_state config to CEL input for encrypted storage of secrets accessible as state.secret. #49207 Add a secret_state configuration field to the CEL input. When configured in a Fleet integration package with secret: true, the values are stored encrypted by Fleet. At runtime, the contents are placed at state.secret and unconditionally redacted in debug logs. The key secret in the plain-text state configuration is reserved and rejected by validation to prevent accidental unencrypted storage of values intended to be secret.
  • Allow string and number arrays in httpjson chained configurations. #49391 #16662
  • Add support for URL and URL query parsing and formatting in the Streaming input CEL environment. #49653 #17875 Metricbeat
  • Add client secret authentication support to Azure App Insights module. #48880 Fixes Elastic Agent
  • Fix an issue that could delay reporting shutdown of Agent components. #49414 #49388
  • Reduce AutoOps logging from info to debug for polling. #49507 #49506 Filebeat
  • Fix Filestream take_over causing file re-ingestion when used with autodiscover. #49632 #49579
  • Fix compatibility of the Journald input with journald/systemd versions < 242. #49445 #48152
  • Add rate-limit backoff to CrowdStrike streaming input oauth2 transport. #49453 Wrap the oauth2 HTTP transport used by the CrowdStrike falcon streaming input with a rate-limit-aware transport that intercepts 429 responses, reads the Retry-After header, and backs off before retrying. This prevents the oauth2 token refresh from generating a burst of unauthorized requests that triggers CrowdStrike's 15-per-minute rate limit. The discover endpoint also returns a retry-after hint to the session-level retry loop as a minimum wait floor.
  • Skip request tracer path validation when tracing is disabled to prevent input startup failures. #49655 The startup path validation in cel, httpjson, http_endpoint, and entity analytics inputs checked whether the tracer config struct was non-nil rather than whether tracing was enabled. Integration package templates always include a tracer block (with enabled defaulting to false), so the struct is never nil. Under the agentless/otel runtime the relative tracer path resolves outside the permitted directory, causing all affected inputs to fail immediately even though tracing was disabled. The config-level Validate methods already used the correct enabled() guard; the startup paths now do the same.
  • Fix Filebeat crash loop when running under Elastic Agent and taking too long to initialise. #49796 #49512 Libbeat
  • Fix a bug where escaped characters in syslog structured data caused an EOF error. #49392 #43944 Metricbeat
  • Fix unnecessary Windows filesystem metricset errors from non-existent volumes. #49553 Fix an issue where filesystem metric collection on Windows could report errors for volumes that are no longer present. Update to gosigar v0.14.4. Winlogbeat
  • Skip record ID gap detection for forwarded Windows events. #49819

Installer type: wix

Architecture Scope Download SHA256
x64 Download 41D514F2AB212BCC1324A896BE5D06BFAB315B9B5133C3C66C5058475FD50424

Details

Homepage
https://www.elastic.co/downloads/beats/packetbeat
License
Elastic-2.0
Publisher
Elastic
Support
https://github.com/elastic/beats/issues
Privacy Policy
https://www.elastic.co/legal/privacy-statement
Copyright
© 2026. Elasticsearch B.V. All Rights Reserved

Older versions (18)

9.3.2
Architecture Scope Download SHA256
x64 Download 350B8C7524950DF64924BC9E0AD64E2C4D0E52F20B2336F02D9632A583C705CC
9.3.1
Architecture Scope Download SHA256
x64 Download FF1FCECAB580FD620771308245472F9E9BCF93E6131962290E41046438015501
9.3.0
Architecture Scope Download SHA256
x64 Download 8CBC80B8EF0B3156EB5118D8BB9CD3BF6B502B91E640FB08E45455B426269282
9.2.4
Architecture Scope Download SHA256
x64 Download 0AACF329014DA9CB3726F490BF88182061C3BA83062870EA7F318584FA9C8D6E
9.2.3
Architecture Scope Download SHA256
x64 Download 3623C8D11445AAB0B9A92AA37BD93FB7DBCE8DF16E3E20F9537896E4374AC3B3
9.2.2
Architecture Scope Download SHA256
x64 Download 10961E77E5F24A6CB5C02779068BDA6846D2EA74665AD219764BB54A037694A7
9.2.1
Architecture Scope Download SHA256
x64 Download 2777395076141D6A30119C9124C25082CAB2D0231BCA7F3ABABCA20B943925C8
9.2.0
Architecture Scope Download SHA256
x64 Download 4DE2544E09FBA860845A5031609B8D4F6225E5E06E75537AF6CAB6EADB78439D
9.1.5
Architecture Scope Download SHA256
x64 Download 1BC375D8DA599460933F4761AB5257A5B4BEB055EA8DC994589309E5F0434C09
9.1.4
Architecture Scope Download SHA256
x64 Download AF193D5B20A9D4211E11BE0E128102707164E549904C677D4E8FD41FD1E011FB
9.1.3
Architecture Scope Download SHA256
x64 Download DC45B759D2D7A9976B11CDDCB95F110027AA9F0A4C6318767ADB64450A0457CB
9.1.1
Architecture Scope Download SHA256
x64 Download 4CF897E38B746DD62944C3C2036568793C2FE976F581B47568D858086FCF0078
9.1.0
Architecture Scope Download SHA256
x64 Download EB4E34D8B641AEAA5907C088963D9776C2955F16AB4AC20D9457D633A102CFE5
9.0.4
Architecture Scope Download SHA256
x64 Download 56D09AF0BF9493F1C110B949EAF7AFBEA11938BEB843412451647E40C6D1868D
9.0.3
Architecture Scope Download SHA256
x64 Download 93654981918DA8F23E306A616826F035684819BEEF8C6D92E606FFBDE2BE76BF
9.0.2
Architecture Scope Download SHA256
x64 Download 5FA83EDA4A0DFF2C196775AEB9748B4E7C842B2CFC0CF2844771CBA26D3A9FAE
9.0.1
Architecture Scope Download SHA256
x64 Download 8EA4EE63FBA2CAF20B036810BAB581875365EA770E358CDE584DCC38D01A80C8
9.0.0
Architecture Scope Download SHA256
x64 Download 6466119DF060A0E05EF299E7E8FBA2BD46B192D150C97293A29AE6B43BEA78BB