Corelight_v2_dns_agg_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (30 columns)

Source: KQL validation test schema

Column Name Type
_path_s string
_system_name_s string
AA_b bool
answers_s string
icann_domain_s string
icann_host_subdomain_s string
icann_tld_s string
id_orig_h_s string
id_orig_p_d real
id_resp_h_s string
id_resp_p_d real
is_trusted_domain_b bool
proto_s string
qclass_d real
qclass_name_s string
qtype_d real
qtype_name_s string
query_s string
RA_b bool
rcode_d real
rcode_name_s string
RD_b bool
rejected_b bool
rtt_d real
TC_b bool
TimeGenerated datetime
trans_id_d string
TTLs_s string
uid_s string
Z_d real

Solutions (1)

This table is used by the following solutions:


Content Items Using This Table (1)

Workbooks (1)

In solution Corelight:

Workbook Selection Criteria
Corelight_Data_Explorer

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
corelight_dns_agg Corelight

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index