# Packetbeat DNS response time nanoseconds instead of microseconds

**URL:** <https://discuss.elastic.co/t/packetbeat-dns-response-time-nanoseconds-instead-of-microseconds/313710>\
**Category:** Kibana\
**Created:** [September 5, 2022, 6:42pm UTC](https://discuss.elastic.co/t/packetbeat-dns-response-time-nanoseconds-instead-of-microseconds/313710 "2022-09-05T18:42:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mayer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mayer/32/42164_2.png) [@mayer](https://discuss.elastic.co/u/mayer)\
**Post date:** [September 5, 2022, 6:42pm UTC](https://discuss.elastic.co/t/packetbeat-dns-response-time-nanoseconds-instead-of-microseconds/313710/1 "2022-09-05T18:42:09Z")

</div>

Dear All,  
I am running ELK stack 8.4.1 on latest Debian. Kibana/Packetbeat shows nice data in the DNS overview. When I move the mouse at DNS Min/Max/Avg Response Time Histogram over the graph I see for example max response time (ns) 20.  
There I am quite sure this can't be nanoseconds, it must be microseconds.  
When I wireshark the traffic I see also values in the range of 10 or 100 microseconds. Not sure if a solution down to nanoseconds would be even possible.

Kind regards  
Hans

--

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 5, 2022, 11:47pm UTC](https://discuss.elastic.co/t/packetbeat-dns-response-time-nanoseconds-instead-of-microseconds/313710/2 "2022-09-05T23:47:25Z")

</div>

Hi @mayer

Can you show us which Visualization / Which Dashboard?

I see it now... hmmm...looking...

Ok Got... It is simply labeled wrong... I was starting to thing there was a major bug...

In the Data View .. .the nanos are converted to ms... so those duration are in fact represented in ms

 ![Screen Shot 2022-09-05 at 5.07.58 PM](https://us1.discourse-cdn.com/elastic/original/3X/9/f/9ffe30e110d55f0b19c00182fe79d40ef0f6ec5f.jpeg)

I suspect the Label in the Default Dashboard never got update to match... with the new setting

So you can just fix the label... by hitting edit on the Dashboard, Edit the Viz and fix the label

 ![Screen Shot 2022-09-05 at 5.10.30 PM](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a1065bacd46dbd656ee06ea27adf818b1eb849b6.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 6, 2022, 12:27am UTC](https://discuss.elastic.co/t/packetbeat-dns-response-time-nanoseconds-instead-of-microseconds/313710/3 "2022-09-06T00:27:11Z")

</div>

~~And you could enter an issue in the Packet Beat Repo if you like.~~

I entered an issue [here](https://github.com/elastic/beats/issues/32983)

@mayer Thanks for finding this! 🙂

---

<div class="post-metadata">

**Author:** ![mayer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mayer/32/42164_2.png) [@mayer](https://discuss.elastic.co/u/mayer)\
**Post date:** [September 6, 2022, 5:44pm UTC](https://discuss.elastic.co/t/packetbeat-dns-response-time-nanoseconds-instead-of-microseconds/313710/4 "2022-09-06T17:44:09Z")

</div>

Hi Stephen,  
many thanks for your reply and the hint to fix this issue.  
But is it really "ms" ( milliseconds ) ? Or should it be microseconds ( 10^-6 of a second ) ? Indeed I see with Wireshark values between some and hundreds microseconds.

Kind regards  
Hans

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 6, 2022, 8:33pm UTC](https://discuss.elastic.co/t/packetbeat-dns-response-time-nanoseconds-instead-of-microseconds/313710/5 "2022-09-06T20:33:44Z")

</div>

Hmmm On my box the ms lined up with what I was seeing...

Example

```auto
$ dig jetbrains.com
...

;; Query time: 21 msec
;; SERVER: 192.168.2.1#53(192.168.2.1)
;; WHEN: Tue Sep 06 13:30:32 PDT 2022
;; MSG SIZE rcvd: 106

....
Couple more times

;; Query time: 0 msec
;; SERVER: 192.168.2.1#53(192.168.2.1)

```

 ![Screen Shot 2022-09-06 at 1.32.59 PM](https://us1.discourse-cdn.com/elastic/original/3X/8/d/8d71800ecfe1aee7b9dd170f4cc356c0828b8adc.jpeg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2022, 8:33pm UTC](https://discuss.elastic.co/t/packetbeat-dns-response-time-nanoseconds-instead-of-microseconds/313710/6 "2022-10-04T20:33:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
