DNS_Summarized_Logs_ip_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Internal Use Table: This table is created and used internally by the DNS Essentials solution. It is written to by playbooks for solution-specific data storage.

Attribute Value
Category Internal
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (7 columns)

Source: KQL validation test schema

Column Name Type
count__d int
DnsQuery_s string
DnsResponseName_s string
EventResultDetails_s string
EventTime_t datetime
SrcIpAddr_s string
TimeGenerated datetime

Solutions (1)

This table is used by the following solutions:


Content Items Using This Table (7)

Analytic Rules (3)

In solution DNS Essentials:

Analytic Rule Selection Criteria
Detect DNS queries reporting multiple errors from different clients - Anomaly Based (ASIM DNS Solution)
Detect excessive NXDOMAIN DNS queries - Anomaly based (ASIM DNS Solution)
Potential DGA(Domain Generation Algorithm) detected via Repetitive Failures - Anomaly based (ASIM DNS Solution)

Hunting Queries (2)

In solution DNS Essentials:

Hunting Query Selection Criteria
Connection to Unpopular Website Detected (ASIM DNS Solution)
[Anomaly] Anomalous Increase in DNS activity by clients (ASIM DNS Solution)

Workbooks (1)

In solution DNS Essentials:

Workbook Selection Criteria
DNSSolutionWorkbook

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index