DNS Analytics
ArchivedThe DNS Analytics normalizes DNS events. You can further customize the searches to perform in-depth analysis.
Release Details
Enhancement
The application has been updated to comply with LogPoint v6.7.0.
Installation
Follow these steps to install the DNS Analytics v5.0.0 plugin:
- Download the DNS Analytics package from the Download section above.
- Add the required DNS server as a device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
Past Release
6.0.0 to 6.6.6 ▾
Enhancement
From now on, the normalized field names are conveniently mapped to the LogPoint taxonomy. Please find the mapping in the table below.
Log Format
Expected Log Format
- DNS Bind
Log Sample
<13>Jan 17 22:11:10 fedora BIND-DNS: 21:11:09.648 queries: info: client 2.2.2.289#55175 (xxx.xxx.xx.net): query: scontent-arn2-1.xx.xxxx.net IN A + (1.1.1.1)secdns 2016 Feb 24 10:27:18 PF: client 1.1.1.1#80: query: A? abc.com. answer: 1/0/0 CNAME abc.com.np., A 1.1.1.4 (185)
To export data to LogPoint, use Syslog collector on port 514 on the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Please sign in to leave a comment.