Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

The Elasticsearch dissector uses UDP port 54328 and TCP port 9300 by default. UDP and TCP packets using these ports run the risk of being mislabeled like this. Simplest way to solve this, since you do not deploy Elasticsearch, is to simple disable the Elasticsearch protocol, through the menu Analyze | Enabled protocols..., search for Elasticsearch in that dialog and uncheck the protocol.