Explore metrics in the ExtraHop system to investigate DNS failures
The DNS (domain name system) protocol is critical for supporting internet traffic. It often works without issues. However, DNS servers are commonly misconfigured or overloaded in IT environments, which can affect internet performance.
There are many ways to explore DNS metrics in the ExtraHop system. In this walkthrough, we’ll show you how to review DNS metrics in a dashboard, navigate to DNS protocol pages, and drill-down on interesting metrics to identify potentially-affected devices.
Specifically, you’ll learn how to answer the following questions:
- Is there a network or DNS issue that is affecting internet performance?
- What are the number of DNS failures on my network?
- Which clients are not responding to my DNS servers?
Additional resources are available for interpreting DNS:
- Learn about interpreting DNS metrics in the ExtraHop system by viewing our online training module, Quick Peek: DNS.
- Learn about problem DNS queries and errors that you can monitor in your own environment by installing the ExtraHop DNS Bundle. This bundle contains a dashboard with pre-configured charts and detailed explanations about key DNS errors.
Prerequisites
- Familiarize yourself with the concepts in this walkthrough by reading the Get started with metrics section of the ExtraHop Web UI Guide.
- You must have access to an ExtraHop Discover appliance with DNS server traffic, or you can perform this walkthrough in the ExtraHop demo.
Identify DNS issues with system dashboards
If a slow internet issue is reported, look at the system dashboards to determine whether the issue is related to network throughput or to the DNS protocol.
Based on these dashboard charts, the network throughput appears okay. Next, we
should investigate our DNS servers. Click the All Activity DNS
chart title to switch to the All Activity page in the
Metrics section of the Web UI.
Thank you for your feedback. Can we contact you to ask follow up questions?