What Beavus Actually Is and How to Work With It
Beavus is a lightweight, open-source packet capture and analysis tool built for network diagnostics on Linux systems. It sits somewhere between tcpdump's raw speed and Wireshark's GUI convenience, but it doesn't try to do either perfectly. It just grabs packets, flags anomalies, and spits out a plain-text report you can grep through. I started using it about three years ago when a client's internal network kept dropping DNS resolutions at random intervals. Wireshark was too heavy to leave running on their aging rack server, and tcpdump output was a wall of text nobody wanted to parse by hand. Beavus was already on the machine for a maintenance script, so I pointed it at eth0 and let it run overnight.
Installing Beavus
The project lives on GitHub, and the latest release is available at github.com/beavus. On Ubuntu or Debian, you can grab the .deb from the releases page and install it with dpkg. On RHEL or Rocky, there's an rpm build, though you might need to install libpcap-dev and nlohmann-json from your distro's repos first. I've also seen people compile from source, which takes about four minutes on a decent machine. After installation, verify it with beavus --version. The current stable release is 2.4.1. If you see an older version number, you're probably running something from your distro's package repo, which tends to lag behind by a few months and sometimes ships with patches that break the anomaly detection module.
Running a Basic Capture
The simplest command is just beavus -i eth0 -d 60, which captures on interface eth0 for 60 seconds and writes a report to stdout. You can redirect it to a file with the -o flag. The default report format is compact enough to read in a terminal window, but if you want the full structured output for parsing, add --format json and pipe it somewhere. One thing most guides don't mention: Beavus does not handle promiscuous mode automatically. If you're trying to sniff traffic on a switched port and you're not getting expected packets, check that the interface is up and that you have permissions. Running it as root fixes the permission issue, but if you'd rather not, add your user to the pcap group and make sure the interface has been set to promisc mode with ip link set eth0 promisc on beforehand. I ran into a specific problem last year where Beavus would silently drop packets on interfaces using RSS (Receive Side Scaling) on newer NICs. The capture appeared to run fine, but the report showed gaps — periods where zero packets were logged despite heavy network activity. The workaround was to pin the capture to a single CPU core using taskset -c 0 beavus -i eth0 -d 120. Once I did that, the gaps disappeared. The developers acknowledged the issue in a GitHub issue but haven't patched it as of the 2.4.1 release, so if you're on a multi-NIC server with RSS enabled, this is something to be aware of.
Anomaly Detection and Flagging
The part that makes Beavus useful instead of just another tcpdump wrapper is its built-in anomaly detection. It watches for common network pathologies — ARP flapping, DHCP starvation attempts, TCP retransmission storms, DNS response timeouts, and malformed packets. When it detects one, it logs the event with a severity level and a timestamp, along with the relevant packet headers. The thresholds are adjustable. The defaults are reasonable for a typical office network, but if you're running this in a data center environment with high baseline traffic, you'll want to tune them. The config file lives at /etc/beavus/config.yaml on most installs. I usually bump retransmission thresholds up by 50 percent in busy environments to avoid noise. A counter-intuitive thing about Beavus's anomaly engine: it treats ICMP rate limits differently depending on whether they come from the local host or pass through it. If you're troubleshooting why a firewall rule seems to be ignored and Beavus isn't flagging the ICMP traffic, check your direction settings. By default, Beavus only analyzes ingress traffic on the specified interface. Add --direction both if you need egress coverage too.
Exporting and Post-Processing
Beavus can export captures in pcap format with the --export-pcap flag, which means you can hand off a file to Wireshark later if you need deep packet inspection. The export includes the flagged anomalies as comments in the pcap, so you can jump straight to them in Wireshark's display filter bar by searching for beavus flags. For automated environments, the JSON output format plays nicely with log aggregation tools. I've had good results feeding it into Elasticsearch with a simple logstash pipeline, though you'll want to write a small grok pattern to handle Beavus's JSON structure since it's not standard syslog format.
Limitations and When to Skip It
Beavus has real limitations. It doesn't support TLS decryption, so if your issue is on an encrypted connection, you're looking at something else. It also struggles with bonded interfaces — I've seen inconsistent results on LACP bonds, and the developers recommend capturing on the individual slave interfaces instead. For VLAN-tagged traffic, it works fine, but you need to specify the VLAN interface explicitly, not the parent interface. If you need long-duration captures spanning days or weeks, Beavus isn't the right tool. It's designed for focused diagnostic windows, typically under a few hours. For longer monitoring, pair it with a proper NPM solution or just use tcpdump with rotation scripts. The project is actively maintained but small. Feature requests sit in GitHub issues for months, and the documentation, while accurate, is thin on edge cases. If you run into something weird, the issue tracker and the #beavus channel on their Discord are where most of the knowledgeable users hang out.