Configure private DNS
Private DNS maps the service hostnames provided for your deployment to the private IP address of the Azure Private Endpoint.
Complete this step after the Private Endpoint has been created and approved.
Before you begin
You need:
- the private Elasticsearch, Kibana, and Fleet hostnames provided for the deployment;
- the Private Endpoint private IP address;
- the Azure VNet or client networks that need to resolve the private endpoints.
Use the hostnames provided by the platform.
Do not derive DNS names from Azure resource names or assume a standard privatelink.* domain.
Configure Azure Private DNS
If your clients use Azure DNS:
- Create or select the Azure Private DNS zone for the deployment's private DNS domain.
- Link the Private DNS zone to the VNet or VNets that need access to the platform.
- Create the required DNS records for the Elasticsearch, Kibana, and Fleet hostnames.
- Point the records to the Private Endpoint private IP address.
- Save the configuration.
Use only the hostnames provided for the deployment.
Hybrid or on-premises DNS
If clients outside Azure use corporate DNS, configure the corporate DNS environment to resolve the deployment's private DNS domain through Azure.
A common design is:
Corporate DNS
↓
Azure DNS Private Resolver
↓
Azure Private DNS
↓
Private Endpoint
Configure conditional forwarding for the deployment's private DNS domain using your organization's supported DNS architecture.
Do not forward queries directly to Azure's internal DNS virtual IP from on-premises networks.
Verify DNS
From each network that needs access, resolve the required service hostnames.
nslookup <service-hostname>
The hostname should resolve to the Private Endpoint private IP address.
Repeat the test for the Elasticsearch, Kibana, and Fleet hostnames you plan to use.
Warning
If a private service hostname resolves to a public IP address, stop here. Complete the DNS configuration before troubleshooting TLS or authentication.
Next step
After private DNS resolves correctly, continue to configure TLS certificates.
If DNS does not resolve as expected, see connectivity issues.