# Detect DNS tunneling

**URL:** <https://discuss.elastic.co/t/detect-dns-tunneling/56587>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [July 28, 2016, 8:30am UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587 "2016-07-28T08:30:50Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![pfe](https://avatars.discourse-cdn.com/v4/letter/p/49beb7/32.png) [@pfe](https://discuss.elastic.co/u/pfe)\
**Post date:** [July 28, 2016, 8:30am UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/1 "2016-07-28T08:30:50Z")

</div>

It`s the first time that i used Packetbeat, and I wanted to know How can we use packetbeat ,elasticsearch to capture DNS traffic and to detect DNS tunneling from my iodine ?

Thank you  
Regards

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 28, 2016, 3:35pm UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/2 "2016-07-28T15:35:02Z")

</div>

Here are some resources to help. They take the approach of looking for abnormally high number of unique sub-domains associated with a domain.

[Blog: Detecting DNS Tunnels with Packetbeat and Watcher](https://www.elastic.co/blog/detecting_dns_tunnels_with_packetbeat_and_watcher)  
[Example Code: DNS Tunnel Detection](https://github.com/elastic/examples/tree/master/packetbeat_dns_tunnel_detection)

There has been one enhancement to Packetbeat 5.0 that makes things easier. We added a field called [`dns.question.etld_plus_one`](https://www.elastic.co/guide/en/beats/packetbeat/master/exported-fields-dns.html#_dns_question_etld_plus_one) that does the work of finding the effective top level domain (ETLD) so you don't have to do it in Logstash or write a scripted field in Elasticsearch. So basically you can just send the Packetbeat data directly to Elasticsearch and don't need scripted fields.

To count the number of unique domains associated with a given ETLD you do a terms aggregation on the `dns.question.etld_plus_one` field then find the cardinality of the `dns.question.name` field within each of bucket.

---

<div class="post-metadata">

**Author:** ![pfe](https://avatars.discourse-cdn.com/v4/letter/p/49beb7/32.png) [@pfe](https://discuss.elastic.co/u/pfe)\
**Post date:** [August 4, 2016, 10:12am UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/3 "2016-08-04T10:12:44Z")

</div>

Hey!

sorry for the inconvenience, I have installed packetbeat and Elasticsearch on the iodine client and I followed the steps mentioned in the Blog but I couldn`t get any information about the DNS Traffic and about the detection of DNS Tunnel,

Could you please explain why I can`t get any output ?

Thanks

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 4, 2016, 3:02pm UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/4 "2016-08-04T15:02:07Z")

</div>

Do you have a working installation of Packetbeat? What versions are you using? Are dns events being indexed into Elasticsearch?

What output do you get from this query? `curl http://<elasticsearch>:9200/packetbeat-*/dns/_count?pretty`

---

<div class="post-metadata">

**Author:** ![pfe](https://avatars.discourse-cdn.com/v4/letter/p/49beb7/32.png) [@pfe](https://discuss.elastic.co/u/pfe)\
**Post date:** [August 4, 2016, 3:40pm UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/5 "2016-08-04T15:40:38Z")

</div>

now I get this:  
{  
"error" : {  
"root\_cause" : [ {  
"type" : "invalid\_index\_name\_exception",  
"reason" : "Invalid index name [packetbeat-_], must not contain the following characters [\, /, , ?, ", \<, \>, |, , ,]",  
"index" : "packetbeat-"  
} ],  
"type" : "invalid\_index\_name\_exception",  
"reason" : "Invalid index name [packetbeat-_], must not contain the following characters [\, /, _, ?, ", \<, \>, |, , ,]",  
"index" : "packetbeat-_"  
},  
"status" : 400

}

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 4, 2016, 3:44pm UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/6 "2016-08-04T15:44:53Z")

</div>

Replace `<elasticsearch>` with the hostname or IP address of your Elasticsearch server.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 4, 2016, 4:05pm UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/7 "2016-08-04T16:05:31Z")

</div>

Looks like you have DNS data indexed in Packetbeat. Here's a sample query to look for some interesting domains.

```auto
curl http://<elasticsearch>:9200/packetbeat-*/dns/_search?pretty -d'
{
  "query": {
    "bool": {
      "filter": {
        "range": {
          "@timestamp": {
            "from": "now-4h"
          }
        }
      },
      "must_not": {
        "terms": {
          "dns.question.etld_plus_one": [
            "akadns.net.",
            "amazonaws.com.",
            "apple.com.",
            "apple-dns.net.",
            "cloudfront.net.",
            "icloud.com.",
            "in-addr.arpa.",
            "google.com.",
            "yahoo.com."
          ]
        }
      }
    }
  },
  "size": 0,
  "aggs": {
    "by_domain": {
      "terms": {
        "size": 0,
        "field": "dns.question.etld_plus_one"
      },
      "aggs": {
        "unique_hostnames": {
          "cardinality": {
            "field": "dns.question.name"
          }
        },
        "total_bytes_in": {
          "sum": {
            "field": "bytes_in"
          }
        },
        "total_bytes_out": {
          "sum": {
            "field": "bytes_out"
          }
        },
        "high_num_hostnames": {
          "bucket_selector": {
            "buckets_path": {
              "unique_hostnames": "unique_hostnames"
            },
            "script": "unique_hostnames > 10"
          }
        }
      }
    }
  }
}'

```

---

<div class="post-metadata">

**Author:** ![pfe](https://avatars.discourse-cdn.com/v4/letter/p/49beb7/32.png) [@pfe](https://discuss.elastic.co/u/pfe)\
**Post date:** [August 5, 2016, 8:11am UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/8 "2016-08-05T08:11:29Z")

</div>

this is what i get chen I tape the command {  
"count" : 46182,  
"\_shards" : {  
"total" : 15,  
"successful" : 15,  
"failed" : 0  
}  
}

To detect tunnel should I install Packetbeat 5.0 because I have the version  
1.2 ?  
where can I capture the traffic when enter the following command  
/var/log/mybeat thiese are the first lines that i get.

"client\_port": 57780,  
"client\_proc": "",  
"client\_server": "",  
"count": 1,  
"direction": "out",  
"dns": {  
"additionals\_count": 0,  
"answers": [  
{  
"class": "IN",  
"data": "[googlehosted.l.googleusercontent.com](http://googlehosted.l.googleusercontent.com)",  
"name": "[lh3.googleusercontent.com](http://lh3.googleusercontent.com)",  
"ttl": 79420,  
"type": "CNAME"  
},  
{  
"class": "IN",  
"data": "172.217.16.161",  
"name": "[googlehosted.l.googleusercontent.com](http://googlehosted.l.googleusercontent.com)",

Also I didn`t understand how can I use these fileds  
(dns.question.etld\_plus\_one)

([dns.question.name](http://dns.question.name))

Thank you and Sorry about the inconvenience  
Regards

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 8, 2016, 9:19pm UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/9 "2016-08-08T21:19:35Z")

</div>

> [@pfe](#):
>
> To detect tunnel should I install Packetbeat 5.0 because I have the version1.2 ?

Yes, the example query/aggregation I posted above requires Packetbeat 5.0 because it uses the `dns.question.etld_plus_one` field. Using Packetbeat 5.0 will simplify the overall setup because it doesn't require Logstash or any of the extra scripts used in blog post and example. You just capture the traffic to Elasticsearch and execute the query I provided. The query provides you with a list of domains that have a high number of unique hostnames. It also provides the total number of bytes used in requests and responses to/from these domains. You can adjust the unique\_domains threshold and you can modify the whitelist.

Here's an example response from the query:

```auto
{
  "took": 1271,
  "timed_out": false,
  "_shards": {
    "total": 63,
    "successful": 63,
    "failed": 0
  },
  "hits": {
    "total": 34829,
    "max_score": 0,
    "hits": []
  },
  "aggregations": {
    "by_domain": {
      "doc_count_error_upper_bound": 37,
      "sum_other_doc_count": 3231,
      "buckets": [
        {
          "key": "sophosxl.net.",
          "doc_count": 2971,
          "unique_hostnames": {
            "value": 1005
          },
          "total_bytes_in": {
            "value": 154718
          },
          "total_bytes_out": {
            "value": 656802
          }
        },
        {
          "key": "syncthing.net.",
          "doc_count": 741,
          "unique_hostnames": {
            "value": 10
          },
          "total_bytes_in": {
            "value": 33973
          },
          "total_bytes_out": {
            "value": 137054
          }
        }
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![pfe](https://avatars.discourse-cdn.com/v4/letter/p/49beb7/32.png) [@pfe](https://discuss.elastic.co/u/pfe)\
**Post date:** [August 12, 2016, 3:58pm UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/10 "2016-08-12T15:58:18Z")

</div>

Hey

I tried to apply the [Example Code: DNS Tunnel Detection]([http://Example](http://Example) Code: DNS Tunnel Detection) but it doesn`t work so please could you explain what kind of query did you use because it doesn`t function for me and also you said that it doesn t require any extra scripts  
could please provide me the query because I have to test it

Thank you !

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 12, 2016, 4:07pm UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/11 "2016-08-12T16:07:16Z")

</div>

> [@andrewkroh](#):
>
> Yes, the example query/aggregation I posted above requires Packetbeat 5.0 because it uses the dns.question.etld\_plus\_one field.

Are you using Packetbeat 5.0?

> [@pfe](#):
>
> so please could you explain what kind of query did you use because it doesnt function for me and also you said that it doesn t require any extra scriptscould please provide me the query because I have to test it

I provided the exact query in [Detect DNS tunneling - #7 by andrewkroh](https://discuss.elastic.co/t/detect-dns-tunneling/56587/7) and also showed an example response in [Detect DNS tunneling - #9 by andrewkroh](https://discuss.elastic.co/t/detect-dns-tunneling/56587/9).

---

<div class="post-metadata">

**Author:** ![pfe](https://avatars.discourse-cdn.com/v4/letter/p/49beb7/32.png) [@pfe](https://discuss.elastic.co/u/pfe)\
**Post date:** [August 14, 2016, 9:57am UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/12 "2016-08-14T09:57:00Z")

</div>

Yes I am using Packetbeat 5.0 and elasticsearch 5.0 i get the DNS traffic  
and I also used the query that you provided but i can't detect dns tunnel

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2016, 8:31am UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/13 "2016-08-18T08:31:19Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 22, 2016, 3:45pm UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/14 "2016-08-22T15:45:42Z")

</div>



---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 22, 2016, 3:54pm UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/15 "2016-08-22T15:54:59Z")

</div>

> [@pfe](#):
>
> I also used the query that you provided but i can't detect dns tunnel

Then what is the query that I provided returning? Maybe you can need to adjust some of the parameters in the query.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:50pm UTC](https://discuss.elastic.co/t/detect-dns-tunneling/56587/16 "2017-07-05T21:50:44Z")

</div>


