"Packetbeat agents sniff the traffic between your application processes, parse on the fly protocols like HTTP, MySQL or REDIS and correlate the messages into transactions.
For each transaction, the agents insert a JSON document into Elasticsearch where they are stored and indexed."
How much performance degradation could be expected from constantly inspecting every packet on your network with libpcap, correlating the packets into transactions and then storing information on every transaction in Elasticsearch?
Also: I noticed that the link to Elasticsearch on the "Getting Started" page is broken (it's missing the ":" after "http"). Here's a working link: http://www.elasticsearch.org