# Missing DNS requests on Windows machine

**URL:** <https://discuss.elastic.co/t/missing-dns-requests-on-windows-machine/286067>\
**Category:** Endpoint Security\
**Created:** [October 6, 2021, 7:53pm UTC](https://discuss.elastic.co/t/missing-dns-requests-on-windows-machine/286067 "2021-10-06T19:53:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![nemhods](https://avatars.discourse-cdn.com/v4/letter/n/48db29/32.png) [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Post date:** [October 6, 2021, 7:53pm UTC](https://discuss.elastic.co/t/missing-dns-requests-on-windows-machine/286067/1 "2021-10-06T19:53:59Z")

</div>

Hey,

I'm investigating outbound DNS connections from an Active Directory Domain Controller. It contacted the DNS server [tm1.edgedns-tm.info](https://otx.alienvault.com/indicator/hostname/tm1.edgedns-tm.info) which is apparently owned by Microsoft. Nothing overly suspicious, but I wanted to check which process did this request, ignoring the system-wide DNS setting.

So I go to check logs from my Elastic Endpoint Integration (7.15 Agent, integration v1.1.1), but there are no traces of a DNS request to that IP.

Maybe it is expected that some system-level DNS request may not be covered by the Endpoint Integration? E.g. requests sent by MS Defender which may be out of reach for the Elastic solution.

I'm fairly certain I searched for the correct parameters. My firewall logs state clearly that it was a connection to 13.107.222.240 (tm1.edgedns-tm.info) on port 53/udp, so nothing fancy. I even searched the entire "logs-\*" pattern for `destination.ip: 13.107.222.240` with sufficiently large time frame - nothing came back. I do see DNS requests from the host in question, recorded by the endpoint integration. Just not to 13.107.222.240.

I can provide Endpoint logs, but I can already state that `%ProgramFiles\Elastic\Agent\data\elastic-agent-x\logs\elastic-agent-json.log` contains only "information" level logs. Agent status is "healthy" in Fleet.

---

<div class="post-metadata">

**Author:** ![Psyhil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/psyhil/32/116080_2.png) [@Psyhil](https://discuss.elastic.co/u/Psyhil)\
**Post date:** [October 7, 2021, 11:23am UTC](https://discuss.elastic.co/t/missing-dns-requests-on-windows-machine/286067/2 "2021-10-07T11:23:51Z")

</div>

You may need to check if you have the correct integration assigned to your endpoint agent policy.  
Under endpoint agent, integrations you should have "Windows" integration added to the policy.

---

<div class="post-metadata">

**Author:** ![nemhods](https://avatars.discourse-cdn.com/v4/letter/n/48db29/32.png) [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Post date:** [October 7, 2021, 12:15pm UTC](https://discuss.elastic.co/t/missing-dns-requests-on-windows-machine/286067/3 "2021-10-07T12:15:17Z")

</div>

Thanks for the ideas. I doubt that this is the issue though.  
For one, the DNS logs should be coming from the Endpoint Security Integration, not the Windows Integration:

 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/c/6/c673dd578265154f48dbd645d39bc7c9de0f1d5a.png)

Then, I already do see DNS requests - except requests to this specific IP.

Lastly, the windows integration is also present in my agent config.

 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d4079d0ffe420a089370baf4e9147da9f7b91b41.png)

---

<div class="post-metadata">

**Author:** ![nemhods](https://avatars.discourse-cdn.com/v4/letter/n/48db29/32.png) [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Post date:** [October 7, 2021, 6:04pm UTC](https://discuss.elastic.co/t/missing-dns-requests-on-windows-machine/286067/4 "2021-10-07T18:04:36Z")

</div>

Hm. I think I've found some of the DNS requests. They can be found with `event.dataset: endpoint.events.network and network.protocol: dns`.  
The events seem to stem from a sysmon-style log that Elastic Endpoint internally uses. They even have a plain text `message` attached.

These events do not have a destination IP attached. Instead of `destination.port`, They use the field `network.destination.port: 53`, which is [not an official ECS field](https://www.elastic.co/guide/en/ecs/current/ecs-network.html) . I think I'll raise an issue on Github about it...

![image](https://us1.discourse-cdn.com/elastic/original/3X/8/7/87e14ecbefe269c32b31a033d2afc561347d2db0.png)

---

<div class="post-metadata">

**Author:** ![nemhods](https://avatars.discourse-cdn.com/v4/letter/n/48db29/32.png) [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Post date:** [October 8, 2021, 7:00am UTC](https://discuss.elastic.co/t/missing-dns-requests-on-windows-machine/286067/5 "2021-10-08T07:00:20Z")

</div>

I've managed to talk to the great @jamesspi on Slack about this, and for future reference:

Currently, the endpoint integration does not log raw UDP 53 traffic. It seems to be an exception because for DNS, there are more higher quality logs available directly from the OS. However, these logs unfortunately don't contain the contacted DNS server IP. So the data I was searching for is not there as it stands right now (7.15).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 5, 2021, 7:01am UTC](https://discuss.elastic.co/t/missing-dns-requests-on-windows-machine/286067/6 "2021-11-05T07:01:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
