Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

DNS Analytics

Archived

The DNS Analytics normalizes DNS events. You can further customize the searches to perform in-depth analysis.

Release Details

Version: 5.0.0
Release date: 2020-02-27
Supported On: 6.7.0 or later
SHA 256: 16821acfaa9898655440e4ab0c8f30bbf13ef94da99e13e3f50a151f2cf201b2
Download

Enhancement

The application has been updated to comply with LogPoint v6.7.0.

Installation

Follow these steps to install the DNS Analytics v5.0.0 plugin:

  1. Download the DNS Analytics package from the Download section above.
  2. Add the required DNS server as a device in LogPoint.
  3. Create a collection policy with the Syslog collector and appropriate processing policy.
  4. Assign the policy to the device.

Past Release

6.0.0 to 6.6.6 ▾
Version: 3.2.0
Release date: 2018-05-17
Supported On: 6.0.0 to 6.6.6
SHA 256: 75670b4e1fa215cdb4f7c65bf8e0cb92a76664e809c44ca3d8b44171adcb6923
Download

Enhancement

From now on, the normalized field names are conveniently mapped to the LogPoint taxonomy. Please find the mapping in the table below.

Log Format

Expected Log Format

  • DNS Bind

Log Sample

<13>Jan 17 22:11:10 fedora BIND-DNS: 21:11:09.648 queries: info: client 2.2.2.289#55175 (xxx.xxx.xx.net): query: scontent-arn2-1.xx.xxxx.net IN A + (1.1.1.1)secdns 2016 Feb 24 10:27:18 PF: client 1.1.1.1#80: query: A? abc.com. answer: 1/0/0 CNAME abc.com.np., A 1.1.1.4 (185)

To export data to LogPoint, use Syslog collector on port 514 on the LogPoint server.

Support

If you have any questions or require assistance, create a support ticket.

Comments

Please sign in to leave a comment.

Follow

Related articles

  • DNS Process Plugin
  • Windows
  • DNS Cleanup Process Plugin
  • Universal Normalizer
  • Azure Log Analytics
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.