# Count total DNS queries

**URL:** <https://discuss.elastic.co/t/count-total-dns-queries/170318>\
**Category:** Kibana\
**Created:** [February 28, 2019, 10:37am UTC](https://discuss.elastic.co/t/count-total-dns-queries/170318 "2019-02-28T10:37:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marko\_Todoric](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marko_todoric/32/52975_2.png) [@Marko\_Todoric](https://discuss.elastic.co/u/Marko_Todoric)\
**Post date:** [February 28, 2019, 10:37am UTC](https://discuss.elastic.co/t/count-total-dns-queries/170318/1 "2019-02-28T10:37:40Z")

</div>

Hello everyone,

I'm trying to figure out the best way to count total DNS Queries per hour or day. I can easily adjust period. But what would be the best way to count this?  
Packetbeat is sending data to elasticsearch and i use kibana to visualize.  
So far I've created a visualization like this:

```
Metrics
Y-Axis Unique count of _id

Buckets
X-Axis @timestamp per hour

```

At first it did the trick and then started displaying errors like "10 of 21 shards failed" with " No results found".  
I could also use:

```
Metrics
Y-Axis Count

Buckets
X-Axis @timestamp per hour

```

That would display me the results but would that be correct way?  
I tried counting the dns.id field but I've noticed that i have a lot of duplicate DNS ID's for different client\_ip addresses so that is definitely not the correct way.  
I could also count the client\_ip's but that way i will not have a timestamp, instead it will just display top 5 IPs with number of hits.

So how am i to reach the most accurate data? Is my second example good enough?  
I have a DNS that receives really large traffic, so i cannot manually count it to make sure 🙂

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [February 28, 2019, 7:59pm UTC](https://discuss.elastic.co/t/count-total-dns-queries/170318/2 "2019-02-28T19:59:44Z")

</div>

The answer might depend on which visualization you use. But a Line visualization with the X-Axis set to Date Histogram is how I might do this.

Setting Y-Axis to Count will count all documents in the index for time period. So I think that's what you want. Or you might try setting Unique Count on the dns.id field to get rid of the duplicates.

---

<div class="post-metadata">

**Author:** ![Marko\_Todoric](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marko_todoric/32/52975_2.png) [@Marko\_Todoric](https://discuss.elastic.co/u/Marko_Todoric)\
**Post date:** [February 28, 2019, 10:26pm UTC](https://discuss.elastic.co/t/count-total-dns-queries/170318/3 "2019-02-28T22:26:31Z")

</div>

That is how i actually have it set. I just forgot to mention that Bucket with the X-Axis is set to Date Histogram. So that's definitely good! Nice to know, thanks!!

As for the other option, if i set it to Unique count dns.id, it will leave out duplicates, yes. But there are multiple different clients (queries from client\_ip) that are using the same dns.id. So those will be ignored. Don't know why. So it will not display correct data. Just for the record, if i set it to unique count dns.id it will show approx 65k hits. If i set X Axis to Date Histogram and Y to count. It will show up as 180k hits. That seems more like accurate result.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 28, 2019, 10:34pm UTC](https://discuss.elastic.co/t/count-total-dns-queries/170318/4 "2019-03-28T22:34:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
