# How do I get the dns.request.registerd\_name field?

**URL:** <https://discuss.elastic.co/t/how-do-i-get-the-dns-request-registerd-name-field/286883>\
**Category:** Elastic Security\
**Created:** [October 16, 2021, 7:49am UTC](https://discuss.elastic.co/t/how-do-i-get-the-dns-request-registerd-name-field/286883 "2021-10-16T07:49:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![polarfox](https://avatars.discourse-cdn.com/v4/letter/p/d2c977/32.png) [@polarfox](https://discuss.elastic.co/u/polarfox)\
**Post date:** [October 16, 2021, 7:49am UTC](https://discuss.elastic.co/t/how-do-i-get-the-dns-request-registerd-name-field/286883/1 "2021-10-16T07:49:04Z")

</div>

Hello all,

I've recently started getting familiar with Elastic Security. I'm currently using the 14-day free trial and I have a very small setup with a single Windows 10 machine enrolled as an agent.

When I click on Security \> Network \> DNS (in Kibana), the graph titled "Top domains by dns.question.registered\_domain" is completely blank, with the text "All values returned zero" in the middle of it. The table beneath titled "Top DNS domains" is also completely blank. Everything under the "HTTP" and "TLS" tabs are completely empty as well.

I've gone to look at the raw logs and I see that the DNS request logs are coming in, but the dns.question.registered\_domain field does not exist in the logs. Could anyone help or point me to documentation where I could find a way to get this field in? I've looked around but everything I've found seems to be related to configuring specific Beats and not the single agent.

It would be great if anyone had any help for me with the TLS and HTTP tabs as well. I would like to get a bit more familiar with JA3 and I think this could be useful.

Thanks!

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [October 16, 2021, 4:32pm UTC](https://discuss.elastic.co/t/how-do-i-get-the-dns-request-registerd-name-field/286883/2 "2021-10-16T16:32:48Z")

</div>

What beats/modules/integrations are u using to ship data. Those will determine what fields are generated and enriched.

---

<div class="post-metadata">

**Author:** ![polarfox](https://avatars.discourse-cdn.com/v4/letter/p/d2c977/32.png) [@polarfox](https://discuss.elastic.co/u/polarfox)\
**Post date:** [October 16, 2021, 8:33pm UTC](https://discuss.elastic.co/t/how-do-i-get-the-dns-request-registerd-name-field/286883/3 "2021-10-16T20:33:35Z")

</div>

Thanks for responding Alex.

I'm using Elastic Agent, and no individual Beat.

I'm using the Endpoint Security integration. Interestingly, it has this dns.question.registered\_domain field listed under "Exported fields."

In the integration settings, I have all Protections enabled and all Event Collections checked as well.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [October 16, 2021, 10:37pm UTC](https://discuss.elastic.co/t/how-do-i-get-the-dns-request-registerd-name-field/286883/4 "2021-10-16T22:37:34Z")

</div>

Are u getting other `dns.*` fields??

---

<div class="post-metadata">

**Author:** ![polarfox](https://avatars.discourse-cdn.com/v4/letter/p/d2c977/32.png) [@polarfox](https://discuss.elastic.co/u/polarfox)\
**Post date:** [October 17, 2021, 8:53am UTC](https://discuss.elastic.co/t/how-do-i-get-the-dns-request-registerd-name-field/286883/5 "2021-10-17T08:53:27Z")

</div>

Yes I am. An example is in the screenshot below:

![Screenshot from 2021-10-17 09-52-11](https://us1.discourse-cdn.com/elastic/original/3X/3/2/3206d094f59292bb7ffa48a417749b1d5878e275.png)

---

<div class="post-metadata">

**Author:** ![polarfox](https://avatars.discourse-cdn.com/v4/letter/p/d2c977/32.png) [@polarfox](https://discuss.elastic.co/u/polarfox)\
**Post date:** [October 17, 2021, 9:10am UTC](https://discuss.elastic.co/t/how-do-i-get-the-dns-request-registerd-name-field/286883/6 "2021-10-17T09:10:14Z")

</div>

I think the DNS request above kinda shows why this field is important from a security perspective. There are so many subdomains and sub-sub-subdomains on [windowsupdate.com](http://windowsupdate.com), but It would be valuable for me to be able to do some analysis based on just the "[windowsupdate.com](http://windowsupdate.com)" and determine that this is a safe domain and move on. This would be much faster than trying to follow every single 4-subdomains-deep name, which I'm sure would change all the time for things like Windows Update, OS or web app telemetry services, etc.

Also I kinda expect the default things to work out of the box LOL.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2021, 9:10am UTC](https://discuss.elastic.co/t/how-do-i-get-the-dns-request-registerd-name-field/286883/7 "2021-11-14T09:10:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
