Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

use netsh trace / pktmon instead of npcap on windows #28900

Closed
agowa opened this issue Nov 9, 2021 · 2 comments
Closed

use netsh trace / pktmon instead of npcap on windows #28900

agowa opened this issue Nov 9, 2021 · 2 comments
Labels
needs_team Indicates that the issue/PR needs a Team:* label

Comments

@agowa
Copy link

agowa commented Nov 9, 2021

Describe the enhancement:
Because of the license issues with npcap (that this project just choose to ignore so far #21801), it would be nice if this project would move to just using the native commands from windows instead.
I.e., "netsh trace" and "pktmon" instead of npcap. With "pktmon etl2pcap, it also provides the same data format as npcap generated.

Describe a specific use case for the enhancement or feature:

Companies that want to deploy packagebeat widely on a large number of devices that would otherwise exceed the npcap license limit of 5 computers. As well as highly regulated environments where every additional software and causes a bunch of bureaucracy and compliance overhead, as npcap will fall out of the risk assessment. Also, many security-aware people consider the presence of the npcap driver already as a sign of compromise, so using the native tools here would allow keeping that "indicator" alive.

@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Nov 9, 2021
@botelastic
Copy link

botelastic bot commented Nov 9, 2021

This issue doesn't have a Team:<team> label.

@jamiehynds
Copy link

@agowa338 we have recently procured an NPCAP redistributable license to address the 5 node limit you mentioned above. We plan on bundling this license with the new Network Packet Capture agent integration (which leverages Packetbeat under the hood) - relevant issue here. Closing this issue as we don't plan on using netsh or pktmon, now that we have an NPCAP license.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs_team Indicates that the issue/PR needs a Team:* label
Projects
None yet
Development

No branches or pull requests

2 participants