# Packetbeat on high volume production Windows-AD-DNS-Servers

**URL:** https://discuss.elastic.co/t/packetbeat-on-high-volume-production-windows-ad-dns-servers/270652
**Category:** Beats
**Tags:** packetbeat
**Created:** [April 20, 2021, 5:41am UTC](https://discuss.elastic.co/t/packetbeat-on-high-volume-production-windows-ad-dns-servers/270652 "2021-04-20T05:41:59Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Mischa\_Diehm](https://avatars.discourse-cdn.com/v4/letter/m/f6c823/32.png) [@Mischa\_Diehm](https://discuss.elastic.co/u/Mischa_Diehm)
#### Post date: [April 20, 2021, 5:41am UTC](https://discuss.elastic.co/t/packetbeat-on-high-volume-production-windows-ad-dns-servers/270652/1 "2021-04-20T05:41:59Z")

</div>

Hi,

we are trying to visualize and permanently record our DNS traffic. The DNS Server is run on Windows 10 and the logs it writes are ok but extending it with packetbeat would increase the visibility a lot. The concerns I have are running packetbeat on such critical infrastructure are

1. security: packetbeat runs with admin priveledges and listens promisc on the network interface. We would only enable the DNS protocol in packetbeat. But the DNS Servers need to be reachable from everywhere in our network and thus anyone on the network can potentially craft malicious DNS packets potentially exploiting a but in packetbeat. Looking at the security record so far I can't see any major threats where this was exploited but it's kin a of not obvious to me to actually determine the risk? Any hints welcome!
2. performance: not so concerned as I think all that can happen here is packetbeat dropping/missing packets. But packetbeat shouldn't infect the overall server performance significantly if I carefully use `max_procs` to be max the cpu's available. Is that correct?

Thanks 1000x and keep up the great work,  
Mischa

---

<div class="post-metadata">

### Author: ![hilt86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilt86/32/20308_2.png) [@hilt86](https://discuss.elastic.co/u/hilt86)
#### Post date: [April 22, 2021, 9:37am UTC](https://discuss.elastic.co/t/packetbeat-on-high-volume-production-windows-ad-dns-servers/270652/2 "2021-04-22T09:37:45Z")

</div>

You could always create a dedicated sensor running packetbeat that gets a copy of the traffic going to your DCs if you don't want to run the software on your DCs

---

<div class="post-metadata">

### Author: ![Mischa\_Diehm](https://avatars.discourse-cdn.com/v4/letter/m/f6c823/32.png) [@Mischa\_Diehm](https://discuss.elastic.co/u/Mischa_Diehm)
#### Post date: [April 23, 2021, 5:11am UTC](https://discuss.elastic.co/t/packetbeat-on-high-volume-production-windows-ad-dns-servers/270652/3 "2021-04-23T05:11:46Z")

</div>

We looked into that but as all of this runs within an ESX environment and there seems no way of getting a permanent (virtual) mirror port this is unfortunately not an option. Or do you have a recommendation to actually tap into trafficflows within virtual environments?

---

<div class="post-metadata">

### Author: ![hilt86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilt86/32/20308_2.png) [@hilt86](https://discuss.elastic.co/u/hilt86)
#### Post date: [April 28, 2021, 6:07am UTC](https://discuss.elastic.co/t/packetbeat-on-high-volume-production-windows-ad-dns-servers/270652/4 "2021-04-28T06:07:08Z")

</div>

sorry haven't used ESX in about 10+ years - there must be a way (dedicate a nic / offload mirroring to a physical switch, etc)...I just depends on how much you want it and what the risk / benefit is in your context.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 26, 2021, 8:08am UTC](https://discuss.elastic.co/t/packetbeat-on-high-volume-production-windows-ad-dns-servers/270652/5 "2021-05-26T08:08:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
