Skip to main content
Skip table of contents

DNS Messages

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
DNS MessagesBase RuleDNS NotificationInformation
DNS : DNS-QuerySub RuleDNS QueryInformation
DNS : DNS-ResponseSub RuleDNS ResponseInformation

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
logid<vmid>NumberThe ID (logid) is a 10-digit field. It is a unique identifier for that specific log.
level<severity>Text\StringEach log entry contains a Level (level) field that indicates the estimated severity of the event that caused the log entry,
srcip<sip>IP AddressIP address of the traffic’s origin
dstip<dip>IP AddressDestination IP address for the web.
qname<dname>Text\String
srcport<sport>NumberPort number of the traffic's origin
dstport<dport>NumberPort number of the traffic's destination.
srcintf<sinterface>Text\StringInterface name of the traffic's origin.
dstintf<dinterface>Text\StringInterface of the traffic's destination.
user<login>Text\StringName of the user
vd<domainorigin>Text\String
Name of the virtual domain in which the log message was recorded.
sessionid<session>Number
ID for the session.
subtype<subject>Text\String
Each log entry contains a subType or Subcategory field
type<policy>Text\StringEach log entry contains a Type (type) or category field that indicates its log type and which log file stores the log entry
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.