DNS traffic is displayed in Kiban, and ICMP is not present
# /etc/packetbeat/packetbeat.yml
packetbeat.interfaces.device: 1
packetbeat.protocols.dns:
ports: [53]
include_authorities: true
include_additionals: true
packetbeat.protocols.icmp:
output.elasticsearch:
hosts: ["localhost:9200"]