# Help with Detecting DNS Tunnels with PacketBeat + Watcher

**URL:** <https://discuss.elastic.co/t/help-with-detecting-dns-tunnels-with-packetbeat-watcher/143537>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [August 8, 2018, 2:22pm UTC](https://discuss.elastic.co/t/help-with-detecting-dns-tunnels-with-packetbeat-watcher/143537 "2018-08-08T14:22:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Madhu\_Neal1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madhu_neal1/32/51135_2.png) [@Madhu\_Neal1](https://discuss.elastic.co/u/Madhu_Neal1)\
**Post date:** [August 8, 2018, 2:22pm UTC](https://discuss.elastic.co/t/help-with-detecting-dns-tunnels-with-packetbeat-watcher/143537/1 "2018-08-08T14:22:00Z")

</div>

Hi @andrewkroh - Hope you doing good!

I would require your help to build Detecting DNS Tunnels with PacketBeat+Watcher using ELK stack 6.0; I believe the current example which is not supported to use in the 6.x stack.

What changes that I need to modify to work with 6.x?

> **[elastic/examples](https://github.com/elastic/examples/tree/master/Security%20Analytics/dns_tunnel_detection)**
>
> Home for Elasticsearch examples available to everyone. It's a great way to get started.

Many Thanks,  
Neal

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [August 10, 2018, 9:08am UTC](https://discuss.elastic.co/t/help-with-detecting-dns-tunnels-with-packetbeat-watcher/143537/2 "2018-08-10T09:08:55Z")

</div>

Hi @Madhu_Neal1

I have managed to make the example work with the 6.0.1 stack with a few changes:

- When invoking `packetbeat`, don't pass the `-waitstop 10` and `-t` flags.
- In `packetbeat-dns.template.json`, rename the `dns` document type to `doc`.
- inline the `dns_transform.painless` script into `unique_hostnames_watch.json`.

Here's the diff:

```auto
diff --git a/Security Analytics/dns_tunnel_detection/packetbeat-dns.template.json b/Security Analytics/dns_tunnel_detection/packetbeat-dns.template.json
index 9083706..c75c022 100644
--- a/Security Analytics/dns_tunnel_detection/packetbeat-dns.template.json
+++ b/Security Analytics/dns_tunnel_detection/packetbeat-dns.template.json
@@ -30,9 +30,9 @@
       }
    },
    "mappings": {
- "dns": {
+ "doc": {
          "properties": {
- "dns": {
+ "doc": {
                "properties": {
                   "question": {
                      "properties": {
diff --git a/Security Analytics/dns_tunnel_detection/unique_hostnames_watch.json b/Security Analytics/dns_tunnel_detection/unique_hostnames_watch.json
index c1d3048..c5da94a 100644
--- a/Security Analytics/dns_tunnel_detection/unique_hostnames_watch.json
+++ b/Security Analytics/dns_tunnel_detection/unique_hostnames_watch.json
@@ -81,7 +81,15 @@
     },
     "transform": {
       "script": {
- "file": "dns_transform"
+ "source": "def alerts = ctx.payload.aggregations.by_domain.buckets.stream().collect(Collectors.toMap(p->p.key,item->[
+ \"total_requests\" : item.doc_count,
+ \"unique_hostnames\" : item.unique_hostnames.value,
+ \"total_bytes_in\" : item.total_bytes_in.value,
+ \"total_bytes_out\" : item.total_bytes_out.value,
+ \"total_bytes\" : item.total_bytes_in.value + item.total_bytes_out.value
+]));
+return [\"alerts\":alerts];"
+
       }
     },
     "actions": {

```

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [August 10, 2018, 9:25am UTC](https://discuss.elastic.co/t/help-with-detecting-dns-tunnels-with-packetbeat-watcher/143537/3 "2018-08-10T09:25:59Z")

</div>

I've sent a PR to update the docs, although maybe it's best to keep separate versions:

> <https://github.com/elastic/examples/pull/230>

---

<div class="post-metadata">

**Author:** ![Madhu\_Neal1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madhu_neal1/32/51135_2.png) [@Madhu\_Neal1](https://discuss.elastic.co/u/Madhu_Neal1)\
**Post date:** [August 10, 2018, 11:05am UTC](https://discuss.elastic.co/t/help-with-detecting-dns-tunnels-with-packetbeat-watcher/143537/4 "2018-08-10T11:05:00Z")

</div>

Adrian, Thanks for modifying the example, now I can deploy this example on 6.x stack successfully.

But when I am trying to deploy unique\_hotnames\_watch.json, I see below error: - Note: I am running elk stack on elastic cloud.

"actions" : [  
{  
"id" : "log\_domains",  
"type" : "logging",  
"status" : "success",  
"logging" : {  
"logged\_text" : "The following domain(s) have a high number of unique hostnames: {pirate.sea.={unique\_hostnames=220, total\_bytes\_in=16716.0, total\_bytes=51877.0, total\_requests=220, total\_bytes\_out=35161.0}}"  
}  
},  
{  
"id" : "email\_alert",  
"type" : "email",  
"status" : "failure",  
"error" : {  
"root\_cause" : [  
{  
"type" : "messaging\_exception",  
"reason" : "failed to send email with subject [DNS Tunnel Alert] via account [work]"  
}  
],  
"type" : "messaging\_exception",  
"reason" : "failed to send email with subject [DNS Tunnel Alert] via account [work]",  
"caused\_by" : {  
"type" : "send\_failed\_exception",  
"reason" : "Invalid Addresses",  
"caused\_by" : {  
"type" : "s\_m\_t\_p\_address\_failed\_exception",  
"reason" : "554 5.7.1 \<'Madhu\>: Recipient address rejected: Access denied\n",  
"caused\_by" : {  
"type" : "s\_m\_t\_p\_address\_failed\_exception",  
"reason" : "554 5.7.1 [gaddem.madhu@gmail.com](mailto:gaddem.madhu@gmail.com): Recipient address rejected: Access denied\n"  
}  
}  
}  
}  
}  
]  
},  
"messages" : []  
}  
}

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 10, 2018, 11:32am UTC](https://discuss.elastic.co/t/help-with-detecting-dns-tunnels-with-packetbeat-watcher/143537/5 "2018-08-10T11:32:00Z")

</div>

Did you whitelist that address with Elastic Cloud? [https://www.elastic.co/guide/en/cloud/current/ec-watcher.html#ec-watcher-whitelist](https://www.elastic.co/guide/en/cloud/current/ec-watcher.html#ec-watcher-whitelist)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 7, 2018, 11:32am UTC](https://discuss.elastic.co/t/help-with-detecting-dns-tunnels-with-packetbeat-watcher/143537/6 "2018-09-07T11:32:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
