# Config Elastic Packetbeat graylog

**URL:** <https://community.graylog.org/t/config-elastic-packetbeat-graylog/12692>\
**Category:** Graylog Central (peer support)\
**Tags:** sidecar, winlogbeat\
**Created:** [November 9, 2019, 1:24pm UTC](https://community.graylog.org/t/config-elastic-packetbeat-graylog/12692 "2019-11-09T13:24:33Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [November 11, 2019, 8:43am UTC](https://community.graylog.org/t/config-elastic-packetbeat-graylog/12692/2 "2019-11-11T08:43:02Z")

</div>

Please don’t install beast plugin for graylog, it is deprecated.  
Normal Input - Beast would be enough.  
Check also this blog post:

> **[Tapping Wires for Lean Security Monitoring: DNS Request Analysis with Open...](https://graylog.org/post/tapping-wires-for-lean-security-monitoring-dns-request-analysis-with-open-source-software/)**
>
> The combined force of virus scanners, firewalls, IDS systems, and a log management system is a great way to protect your network. We would like to introduce an additional method of security monitoring.

And this:

> [@Packebeat Input](https://community.graylog.org/t/packebeat-input/11729/3):
>
> Hi Jan, thanks for your support. Actually I solved the problem. I’m writing the solution right here in the hope somebody would find it useful. I found that the only way to have Packetbeat working with Graylog is to let it be run by Sidecar. So I needed to configure a new log collector manually (I found only winlogbeat, filebeat and nxlog template, despite on what I read on the website announcing version 3) and pushing this configuration: # Needed for Graylog fields\_under\_root: true fields.col…

---

_[View the full topic](https://community.graylog.org/t/config-elastic-packetbeat-graylog/12692)._
