# Datafeed \[datafeed-packetbeat\_dns\_tunneling\] cannot retrieve data because no index matches datafeed's indices \[packetbeat-\*\]

**URL:** <https://discuss.elastic.co/t/datafeed-datafeed-packetbeat-dns-tunneling-cannot-retrieve-data-because-no-index-matches-datafeeds-indices-packetbeat/334356>\
**Category:** Kibana\
**Tags:** elastic-stack-machine-learning\
**Created:** [May 25, 2023, 5:27pm UTC](https://discuss.elastic.co/t/datafeed-datafeed-packetbeat-dns-tunneling-cannot-retrieve-data-because-no-index-matches-datafeeds-indices-packetbeat/334356 "2023-05-25T17:27:29Z")\
**Posts on this page:** 1\
**Showing post:** 14

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 12, 2023, 3:17am UTC](https://discuss.elastic.co/t/datafeed-datafeed-packetbeat-dns-tunneling-cannot-retrieve-data-because-no-index-matches-datafeeds-indices-packetbeat/334356/14 "2023-06-12T03:17:20Z")

</div>

Well OK, I just looked into it and looks like the ML jobs are actually there ... you just need to create them with the correct data view... took me 5 mins. There is one hitch there is a slight but important miss-configuration that will need to be corrected i.e. the correct `event.dataset` ... I will show you how.

I understand there is already a PR to fix this, I don't have it handy

EDIT 8.8.0 should already be [fixed](https://github.com/elastic/kibana/blob/main/x-pack/plugins/ml/server/models/data_recognizer/modules/security_packetbeat/ml/datafeed_packetbeat_dns_tunneling.json#L10),  
8.7.1 still has this error

1st I am doing this with Elastic Agent Network Capture -\> Elasticsearch  
(No logstash in the middle although that should work according to the documentation)

Assumes agent is sending data

Go To ML - Jobs - Create Job

 ![Screenshot 2023-06-11 at 7.02.41 PM](https://us1.discourse-cdn.com/elastic/original/3X/3/e/3e408bef744717b6d576cb3562624dcf82f27f2e.png)

Select the Correct Data View `logs-network_traffic`

 ![Screenshot 2023-06-11 at 7.04.25 PM](https://us1.discourse-cdn.com/elastic/original/3X/8/5/8595fb261d63b39dbd17745ae0b16fc151b3db42.png)

When you do that it will recognize it and then Select The Correct Job Group a little confusing because it says packetbeat (that should get cleaned up)

Select it

 ![Screenshot 2023-06-11 at 7.05.15 PM](https://us1.discourse-cdn.com/elastic/original/3X/6/f/6f91129acd49c62514040b44cc42934cfdbfcd0a.png)

And you will get this screen and select Create Jobs

 ![Screenshot 2023-06-11 at 7.05.27 PM](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7ef563b97b7a1715ee2fdc2a70c5f5fedebeedaf.jpeg)

You need to go in and make one edit...

 ![Screenshot 2023-06-11 at 8.10.30 PM](https://us1.discourse-cdn.com/elastic/original/3X/6/5/65eeeed0be87d9e38a23aa66e7bc6c7011cadb80.jpeg)

Edit the Data Feed (the even.dataset is wrong

 ![Screenshot 2023-06-11 at 7.17.44 PM](https://us1.discourse-cdn.com/elastic/original/3X/a/3/a3e835c3178d7b1b8066eb270a094367724b29f3.png)

```auto
{
  "bool": {
    "filter": [
      {
        "term": {
          "event.dataset": "network_traffic.dns" <!---- THIS 
        }
      },

```

Save and then Test the Data Feed ...

Should look something like this..

 ![Screenshot 2023-06-11 at 7.17.59 PM](https://us1.discourse-cdn.com/elastic/original/3X/0/7/0797c3f09061bf84495899f352d57693a6973a34.png)

And Whalluh you have the correct jobs pulling from the correct data view, You can just start it

You can start it when you are ready.... Probably need to do the same with the others the `event.dataset`

 ![Screenshot 2023-06-11 at 8.14.41 PM](https://us1.discourse-cdn.com/elastic/original/3X/2/6/267c3b985b820f569e21d864dc501cfb5ee66e0e.png)  
will be incorrect

---

_[View the full topic](https://discuss.elastic.co/t/datafeed-datafeed-packetbeat-dns-tunneling-cannot-retrieve-data-because-no-index-matches-datafeeds-indices-packetbeat/334356)._
