# Windows ETW logs (DNSServer Analytics logs) not getting ingested

**URL:** <https://discuss.elastic.co/t/windows-etw-logs-dnsserver-analytics-logs-not-getting-ingested/368606>\
**Category:** Elastic Agent\
**Tags:** elastic-stack-security\
**Created:** [October 10, 2024, 8:33am UTC](https://discuss.elastic.co/t/windows-etw-logs-dnsserver-analytics-logs-not-getting-ingested/368606 "2024-10-10T08:33:11Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![suhasbhatt101](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@suhasbhatt101](https://discuss.elastic.co/u/suhasbhatt101)\
**Post date:** [October 10, 2024, 8:33am UTC](https://discuss.elastic.co/t/windows-etw-logs-dnsserver-analytics-logs-not-getting-ingested/368606/1 "2024-10-10T08:33:11Z")

</div>

I am trying to ingest DNSServer Analytics logs to my ELK stack (V-8.14) but the logs are not getting ingested, below is the configurations i added in my elastic-agent.yml file:

Trial 1:

```auto
   - type: etw
     id: etw-dnsserver
     enabled: true
     provider.name: Microsoft-Windows-DNSServer
     session_name: DNSServer-Analytical
     trace_level: verbose
     match_any_keyword: 0x8000000000000000
     match_all_keyword: 0  

```

Trial 2: using the path of the file,

```auto
   - type: etw
     enabled: true
     id: etw-dnsserver-session
     file: "C:\WINDOWS\System32\Winevt\Logs\Microsoft-Windows-DNSServer%4Analytical.etl"  

```

I got this configurations from elastic documentation : [ETW input | Filebeat Reference [8.15] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-etw.html)

i also directly tried with filebeat using the path but the data comes in a encoded format which was not readable.

Elastic stack version : 18.4  
Elastic agent version: 18.4

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [October 16, 2024, 4:48pm UTC](https://discuss.elastic.co/t/windows-etw-logs-dnsserver-analytics-logs-not-getting-ingested/368606/2 "2024-10-16T16:48:12Z")

</div>

Isn't this the integration you need [Microsoft DNS Server | Documentation](https://www.elastic.co/docs/current/integrations/microsoft_dnsserver)

---

<div class="post-metadata">

**Author:** ![suhasbhatt101](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@suhasbhatt101](https://discuss.elastic.co/u/suhasbhatt101)\
**Post date:** [November 5, 2024, 8:14am UTC](https://discuss.elastic.co/t/windows-etw-logs-dnsserver-analytics-logs-not-getting-ingested/368606/3 "2024-11-05T08:14:59Z")

</div>

I am using the same integration, and given the above mentioned configurations in agent file but still data is not coming.

---

<div class="post-metadata">

**Author:** ![marc.guasch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marc.guasch/32/74642_2.png) [@marc.guasch](https://discuss.elastic.co/u/marc.guasch)\
**Post date:** [November 5, 2024, 9:28am UTC](https://discuss.elastic.co/t/windows-etw-logs-dnsserver-analytics-logs-not-getting-ingested/368606/4 "2024-11-05T09:28:38Z")

</div>

Are you using filebeat or the integration to try this out?

Something to check out is if you have the events enabled, since DNS Analytical events are disabled by default. You need to follow the [guide](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn800669(v=ws.11)#to-enable-dns-diagnostic-logging) in order to enable them.

---

<div class="post-metadata">

**Author:** ![suhasbhatt101](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@suhasbhatt101](https://discuss.elastic.co/u/suhasbhatt101)\
**Post date:** [November 22, 2024, 8:54am UTC](https://discuss.elastic.co/t/windows-etw-logs-dnsserver-analytics-logs-not-getting-ingested/368606/5 "2024-11-22T08:54:47Z")

</div>

I am using the Integration configurations inside my elastic agent.

The DNS analytics logs are enabled and i can see them in windows. But not getting ingested to Elastic search

---

<div class="post-metadata">

**Author:** ![kareldecloedt](https://avatars.discourse-cdn.com/v4/letter/k/7cd45c/32.png) [@kareldecloedt](https://discuss.elastic.co/u/kareldecloedt)\
**Post date:** [November 22, 2024, 2:58pm UTC](https://discuss.elastic.co/t/windows-etw-logs-dnsserver-analytics-logs-not-getting-ingested/368606/6 "2024-11-22T14:58:31Z")

</div>

I am trying to setup the same integration.

No Data Stream is created for Elastic-DNSServer-Analytical  
The Data Stream does work for Microsoft-Windows-DNSServer/Audit

I followed the guide to enable ETW tracing.

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [December 18, 2024, 9:25pm UTC](https://discuss.elastic.co/t/windows-etw-logs-dnsserver-analytics-logs-not-getting-ingested/368606/7 "2024-12-18T21:25:00Z")

</div>

Were you able to figure this out?

---

<div class="post-metadata">

**Author:** ![suhasbhatt101](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@suhasbhatt101](https://discuss.elastic.co/u/suhasbhatt101)\
**Post date:** [January 10, 2025, 6:38am UTC](https://discuss.elastic.co/t/windows-etw-logs-dnsserver-analytics-logs-not-getting-ingested/368606/8 "2025-01-10T06:38:03Z")

</div>

I was able to get the DNSServer Analytics data with ETW configuration,  
but observed that the data stops when elastic agent restarts.

when i investigate i see error log that :  
Input 'etw' failed with: realtime session could not be created: session already exists: Cannot create a file when that file already exists.

so etw creates a session and collects data, but when agent is restarted, it is not able create a new session or get data from existing session.

any solution to this ?

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [January 23, 2025, 12:28am UTC](https://discuss.elastic.co/t/windows-etw-logs-dnsserver-analytics-logs-not-getting-ingested/368606/9 "2025-01-23T00:28:58Z")

</div>

Can you share your configuration so I can attempt to reproduce?

---

<div class="post-metadata">

**Author:** ![Mario\_22](https://avatars.discourse-cdn.com/v4/letter/m/4491bb/32.png) [@Mario\_22](https://discuss.elastic.co/u/Mario_22)\
**Post date:** [January 28, 2025, 10:52am UTC](https://discuss.elastic.co/t/windows-etw-logs-dnsserver-analytics-logs-not-getting-ingested/368606/10 "2025-01-28T10:52:02Z")

</div>

I have a the same problem.  
I have data from Audit, but I don't from Analytical.

After added path to this file, the logs was load to index.

C:\Windows\System32\Winevt\Logs\Microsoft-Windows-DNSServer%4Analytical.etl

But that didn't still work.

Configuration:

```auto
Session-Name: DNSServer-Analytical
File:
C:\Windows\System32\Winevt\Logs\Microsoft-Windows-DNSServer%4Analytical.etl
Match all keyword: 
0x8000000000000000
Ingest pipeline: logs-microsoft_dnsserver.analytical-1.0.1
Mapping: 
logs-microsoft_dnsserver.analytical@package
logs-microsoft_dnsserver.analytical@custom

```

Elastic-Agent version 8.17.0

---

<div class="post-metadata">

**Author:** ![syk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syk/32/141533_2.png) [@syk](https://discuss.elastic.co/u/syk)\
**Post date:** [February 21, 2025, 7:18am UTC](https://discuss.elastic.co/t/windows-etw-logs-dnsserver-analytics-logs-not-getting-ingested/368606/11 "2025-02-21T07:18:45Z")

</div>

The description of the integration states:

"_When specifying a provider, a new session is created. This controls the name for the new ETW session it will create. If not specified, the session will be named using the provider ID prefixed by 'Elastic-'._":

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/9/090a1a5228062b77c26baf23e4a86909012c76e1.png)

According to the configuration @Mario_22 posted - the Session-Name is not prefixed with "Elastic-" (so a "_provider was specified_"..?)  
And according to the error-message @suhasbhatt101 provided there already exists a session.. (so "_a new session is created_")

Seems something got messed up with the specification of the ETW-Providers?  
Maybe this helps:

> **[Windows ETW (Event Tracing for Windows)](https://benjitrapp.github.io/defenses/2024-02-11-etw/)**
>
> Event Tracing for Windows (ETW) provides a mechanism to trace and log events that are raised by user-mode applications and kernel-mode drivers. ETW is implemented in the Windows operating system and provides developers a fast, reliable, and versatile...

---

<div class="post-metadata">

**Author:** ![Mario\_22](https://avatars.discourse-cdn.com/v4/letter/m/4491bb/32.png) [@Mario\_22](https://discuss.elastic.co/u/Mario_22)\
**Post date:** [March 20, 2025, 2:21pm UTC](https://discuss.elastic.co/t/windows-etw-logs-dnsserver-analytics-logs-not-getting-ingested/368606/12 "2025-03-20T14:21:38Z")

</div>

It finally works.

For some reason it stopped working (maybe a Windows update). And there was a problem with connecting to the Session. It's worth checking

> Get-EtwTraceProvider -guid '{EB79061A-A566-4698-9119-3ED2807060E7}'

how many sessions there are. And it seems that restarting the integration and DNS settings will allow connecting to the session, or will create a new one.

In my case, something was blocking (or duplicating the session)
