# DNS traffic

**URL:** <https://discuss.elastic.co/t/dns-traffic/56617>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [July 28, 2016, 11:42am UTC](https://discuss.elastic.co/t/dns-traffic/56617 "2016-07-28T11:42:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pfe](https://avatars.discourse-cdn.com/v4/letter/p/49beb7/32.png) [@pfe](https://discuss.elastic.co/u/pfe)\
**Post date:** [July 28, 2016, 11:42am UTC](https://discuss.elastic.co/t/dns-traffic/56617/1 "2016-07-28T11:42:21Z")

</div>

Hello everyone !

Please could you explain to me how can I use Packetbeat to monitor DNS traffic

Thank you  
Ragards

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 28, 2016, 2:59pm UTC](https://discuss.elastic.co/t/dns-traffic/56617/2 "2016-07-28T14:59:17Z")

</div>

DNS capturing [is enabled](https://github.com/elastic/beats/blob/1.2/packetbeat/etc/packetbeat.yml#L19-L23) in the default configuration file. So just follow the [Getting Started Guide for Packetbeat](https://www.elastic.co/guide/en/beats/packetbeat/current/packetbeat-installation.html) and you should be up and running.

---

<div class="post-metadata">

**Author:** ![pfe](https://avatars.discourse-cdn.com/v4/letter/p/49beb7/32.png) [@pfe](https://discuss.elastic.co/u/pfe)\
**Post date:** [July 28, 2016, 5:57pm UTC](https://discuss.elastic.co/t/dns-traffic/56617/3 "2016-07-28T17:57:32Z")

</div>

ok thank you for your response, but from where can I capture the traffic and analyze it ?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 28, 2016, 7:37pm UTC](https://discuss.elastic.co/t/dns-traffic/56617/4 "2016-07-28T19:37:43Z")

</div>

Packetbeat listens to the traffic on any one of the computer's network interfaces. So you install it on a server you will only see traffic to and from that server. If you want to see traffic from multiple devices on a network, then a common solution is to configure a port mirror on one of your managed switches or deploy a network tap device and feed that traffic to a free NIC on the server running Packetbeat.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2016, 11:42am UTC](https://discuss.elastic.co/t/dns-traffic/56617/5 "2016-08-18T11:42:25Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
