Would you like to learn how to install Packetbeat on Ubuntu Linux? In this tutorial, we are going to show you how to install the Packetbeat service on a computer running Ubuntu Linux and send the network information to an ElasticSearch server.

• Ubuntu 18
• Ubuntu 19
• ElasticSearch 7.6.2
• Kibana 7.6.2
• Packetbeat 7.6.2

In our example, The ElastiSearch server IP address is 192.168.100.7.

Tutorial Packetbeat - Installation on Ubuntu Linux

Set a hostname using the command named hostnamectl.

Copy to Clipboard

Reboot the computer.

Copy to Clipboard

Install the required packages.

Copy to Clipboard

Download and install the Packetbeat package.

Copy to Clipboard

Edit the Packetbeat configuration file named packetbeat.yml.

Copy to Clipboard

Here is the original file, before our configuration.

Copy to Clipboard

Here is the file with our configuration.

Copy to Clipboard

In our example, we configured the Packetbeat service to send data to the ElasticSearch server 192.168.100.7.

In our example, we configured the Packetbeat service to connect to the Kibana server 192.168.100.7.

Use the following command to create the Packetbeat dashboards on the Kibana server.

Copy to Clipboard

Start the Packetbeat service.

Copy to Clipboard

Configure the Packetbeat service to start during boot time.

Copy to Clipboard

Congratulations! You have finished the Packetbeat installation on Ubuntu Linux.

Kibana - Accessing the Packetbeat Dashboard

Open your browser and enter the IP address of your Kibana server plus :5601.

In our example, the following URL was entered in the Browser:

• http://192.168.100.7:5601

The Kibana web interface should be presented

Kibana menus

On the Visualize and Explore Data area, select the Dashboard option.

Kibana dashboards

Search for dashboards named Packetbeats.

Packetbeat Dashboards

Select the desired Packetbeat dashboard.

Packetbeat Dashboard Overview

Congratulations! You are able to access the Packetbeat information on the Kibana server.