# Dns Indexing Problem

**URL:** <https://discuss.elastic.co/t/dns-indexing-problem/120349>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [February 18, 2018, 11:41am UTC](https://discuss.elastic.co/t/dns-indexing-problem/120349 "2018-02-18T11:41:32Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![harrunisk](https://avatars.discourse-cdn.com/v4/letter/h/bc79bd/32.png) [@harrunisk](https://discuss.elastic.co/u/harrunisk)\
**Post date:** [February 18, 2018, 11:41am UTC](https://discuss.elastic.co/t/dns-indexing-problem/120349/1 "2018-02-18T11:41:32Z")

</div>

Hi all.  
I am trying to do this [example](https://github.com/elastic/examples/blob/master/Machine%20Learning/Security%20Analytics%20Recipes/dns_data_exfiltration/EXAMPLE.md). Packetbeat can capture traffic but there is indexing problem about dns. I have already installed elasticsearch, kibana, x-pack, packetbeat and logstash. I haven't configured logstash because we are not using it in this example. I have installed ingest processor as well. I don't have any authentication problem.  
`curl localhost:9200/packetbeat-*/_refresh -u elastic:changeme`  
`{"_shards":{"total":30,"successful":15,"failed":0}}`

`curl localhost:9200/packetbeat-*/_count -u elastic:changeme`  
`{"count":1477,"_shards":{"total":15,"successful":15,"skipped":0,"failed":0}}`  
Above answer means that packetbeat can capture traffic and sends to Elasticsearch.

`curl localhost:9200/packetbeat-*/dns/_count -u elastic:changeme`  
`{"count":0,"_shards":{"total":15,"successful":15,"skipped":0,"failed":0}}`  
I don't have any dns index.

My packetbeat.yml

**packetbeat.interfaces.device: enp3s0  
packetbeat.protocols.dns:  
ports: [53]  
include\_authorities: true  
include\_additionals: true  
name: test  
output.elasticsearch:  
hosts: ["localhost:9200"]  
protocol: "https"  
username: "elastic"  
password: "changeme"  
pipeline: "extract\_subdomain"  
logging.selectors: ["\*"]**

Thank you for your helps in advance.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 18, 2018, 12:37pm UTC](https://discuss.elastic.co/t/dns-indexing-problem/120349/2 "2018-02-18T12:37:39Z")

</div>

Which version of Elasticsearch and Packetbeat are you using?

---

<div class="post-metadata">

**Author:** ![harrunisk](https://avatars.discourse-cdn.com/v4/letter/h/bc79bd/32.png) [@harrunisk](https://discuss.elastic.co/u/harrunisk)\
**Post date:** [February 18, 2018, 1:33pm UTC](https://discuss.elastic.co/t/dns-indexing-problem/120349/3 "2018-02-18T13:33:14Z")

</div>

packetbeat version 6.2.1 (amd64), libbeat 6.2.1

Elastic search  
{  
"name" : "jKGZwsu",  
"cluster\_name" : "elasticsearch",  
"cluster\_uuid" : "Q0VREhc1SpKye\_PG4ssm8w",  
"version" : {  
"number" : "6.2.0",  
"build\_hash" : "37cdac1",  
"build\_date" : "2018-02-01T17:31:12.527918Z",  
"build\_snapshot" : false,  
"lucene\_version" : "7.2.1",  
"minimum\_wire\_compatibility\_version" : "5.6.0",  
"minimum\_index\_compatibility\_version" : "5.0.0"  
},  
"tagline" : "You Know, for Search"  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 18, 2018, 1:47pm UTC](https://discuss.elastic.co/t/dns-indexing-problem/120349/4 "2018-02-18T13:47:01Z")

</div>

In Elasticsearch 6.x, only a single type is allowed per index. Packetbeat therefore indexes all documents as type `doc` and instead use a field called `type` to distinguish between different types of traffic. In your last count query you are looking for documents with the document type `dns`, which is why you're not getting any hits. Instead try something like this:

```auto
curl -XGET 'localhost:9200/packetbeat-*/_count?pretty' -u elastic:changeme -H 'Content-Type: application/json' -d'
{
    "query" : {
        "term" : { "type" : "dns" }
    }
}'

```

---

<div class="post-metadata">

**Author:** ![harrunisk](https://avatars.discourse-cdn.com/v4/letter/h/bc79bd/32.png) [@harrunisk](https://discuss.elastic.co/u/harrunisk)\
**Post date:** [February 18, 2018, 2:19pm UTC](https://discuss.elastic.co/t/dns-indexing-problem/120349/5 "2018-02-18T14:19:15Z")

</div>

```
{
  "count" : 691,
  "_shards" : {
    "total" : 5,
    "successful" : 5,
    "skipped" : 0,
    "failed" : 0
  }
}
    {
  "count" : 691,
  "_shards" : {
    "total" : 5,
    "successful" : 5,
    "skipped" : 0,
    "failed" : 0
  }
}

```

thanks for your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2018, 2:19pm UTC](https://discuss.elastic.co/t/dns-indexing-problem/120349/6 "2018-03-18T14:19:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
