# Packetbeat\_dns\_tunneling ML job Bug

**URL:** <https://discuss.elastic.co/t/packetbeat-dns-tunneling-ml-job-bug/376661>\
**Category:** Elastic Security\
**Created:** [April 2, 2025, 4:56am UTC](https://discuss.elastic.co/t/packetbeat-dns-tunneling-ml-job-bug/376661 "2025-04-02T04:56:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![warren.cruz](https://avatars.discourse-cdn.com/v4/letter/w/f08c70/32.png) [@warren.cruz](https://discuss.elastic.co/u/warren.cruz)\
**Post date:** [April 2, 2025, 4:56am UTC](https://discuss.elastic.co/t/packetbeat-dns-tunneling-ml-job-bug/376661/1 "2025-04-02T04:56:59Z")

</div>

The `packetbeat_dns_tunneling` ML job still expects that the Packetbeat index template is applied. This is an issue when Elastic Agent is used.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/a/8a798463691be9a4c2686a3feb361c5e8735b486.jpeg)

Issue was previously discussed here: [Datafeed [datafeed-packetbeat\_dns\_tunneling] cannot retrieve data because no index matches datafeed's indices [packetbeat-\*] - #14 by stephenb](https://discuss.elastic.co/t/datafeed-datafeed-packetbeat-dns-tunneling-cannot-retrieve-data-because-no-index-matches-datafeeds-indices-packetbeat/334356/14)

---

<div class="post-metadata">

**Author:** ![NickFritts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickfritts/32/47189_2.png) [@NickFritts](https://discuss.elastic.co/u/NickFritts)\
**Post date:** [April 2, 2025, 10:22am UTC](https://discuss.elastic.co/t/packetbeat-dns-tunneling-ml-job-bug/376661/2 "2025-04-02T10:22:00Z")

</div>

Hi @warren.cruz

I don't see it in your screenshot, but can you confirm what version of the stack and agent that you're using to hit the problem?

Thanks,  
-nf

---

<div class="post-metadata">

**Author:** ![warren.cruz](https://avatars.discourse-cdn.com/v4/letter/w/f08c70/32.png) [@warren.cruz](https://discuss.elastic.co/u/warren.cruz)\
**Post date:** [April 3, 2025, 1:54am UTC](https://discuss.elastic.co/t/packetbeat-dns-tunneling-ml-job-bug/376661/3 "2025-04-03T01:54:04Z")

</div>

Hi, Nick.

I'm using the Elastic Cloud, Version 8.16.6.

That error pops up when the ML job is started.

I managed to address the error by manually applying the Packetbeat index template.

Was wondering if this needs to be fixed so that Elastic Agent-driven integrations won't have to manually apply the Packetbeat index template.

Thanks.
