# Complete DNS activity coverage in endpoint

**URL:** <https://discuss.elastic.co/t/complete-dns-activity-coverage-in-endpoint/288259>\
**Category:** Endpoint Security\
**Created:** [November 2, 2021, 7:28pm UTC](https://discuss.elastic.co/t/complete-dns-activity-coverage-in-endpoint/288259 "2021-11-02T19:28:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nemhods](https://avatars.discourse-cdn.com/v4/letter/n/48db29/32.png) [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Post date:** [November 2, 2021, 7:28pm UTC](https://discuss.elastic.co/t/complete-dns-activity-coverage-in-endpoint/288259/1 "2021-11-02T19:28:18Z")

</div>

Hey,

I've noticed that the rule [DNS Activity to the Internet](https://www.elastic.co/guide/en/security/7.15/dns-activity-to-the-internet.html#dns-activity-to-the-internet-history) does not work with Elastic Endpoint data, even when I explicitly contact an external DNS server from my machines that are covered by Elastic Endpoint.  
I dug a bit further, and it seems that

- on linux, no UDP traffic is captured _at all_, including DNS (53/udp)
- on Windows, it is captured through a sysmon-like interface, but without `destination.ip` information (see my other post: [https://discuss.elastic.co/t/missing-dns-requests-on-windows-machine](https://discuss.elastic.co/t/missing-dns-requests-on-windows-machine))

I understand that it's difficult to record UDP traffic because it can't be naturally aggregated into connections like TCP. I would love to see more comprehensive coverage of DNS activity on both windows and linux in the future though. Is this planned?

From personal experience investigating suspicious activity, it would be great to have full coverage of

- `dns.question.name`
- `dns.answer.data`
- `destination.ip` (of the DNS server), destination.port, network.protocol (DNS, DoT, DoH)
- `process.name / executable`

Especially the last part is crucial to tie together what process actually caused a lookup to a domain that is malicious.

Finally: Is there an official place to file requests for the Endpoint integration? It doesn't seem to be on Github.

Thanks!

---

<div class="post-metadata">

**Author:** ![bradenpreston](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bradenpreston/32/56729_2.png) [@bradenpreston](https://discuss.elastic.co/u/bradenpreston)\
**Post date:** [November 23, 2021, 5:00pm UTC](https://discuss.elastic.co/t/complete-dns-activity-coverage-in-endpoint/288259/2 "2021-11-23T17:00:16Z")

</div>

Thanks @nemhods - this is great feedback. We are looking to improve our eventing collection and will take this input!

Really appreciate you working with endpoint.

Braden

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 21, 2021, 5:00pm UTC](https://discuss.elastic.co/t/complete-dns-activity-coverage-in-endpoint/288259/3 "2021-12-21T17:00:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
