NXLogDNSLogs

NXLogDNSLogs Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index


Attribute Value
Publisher NXLog
Support Tier Partner
Support Link https://nxlog.co/support-tickets/add/support-ticket
Categories domains
Version 3.0.0
Author NXLog
First Published 2022-05-24
Solution Folder NXLogDnsLogs

The NXLog DNSLogs solution for Microsoft Sentinel enables you to ingest DNS server events. NXLog DNSLogs uses Event Tracing for Windows (ETW) for collecting both Audit and Analytical DNS server events.The NXLog im_etw module reads event tracing data directly for maximum efficiency, without the need to capture the event trace into an .etl file.

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

a. Azure Monitor HTTP Data Collector API

Contents

Data Connectors

This solution provides 1 data connector(s):

🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Tables Used

This solution uses 1 table(s):

Table Used By Connectors Used By Content
NXLog_DNS_Server_CL 🔶 NXLog DNS Logs -

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 1 content item(s):

Content Type Count
Parsers 1

Parsers

Name Description Tables Used
ASimDnsMicrosoftNXLog - -

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index