DNS Query Message

Classification

Rule Name

Rule Type

Common Event

Classification

DNS Query Message

Base Rule

DNS Query

Information

Suspicious DNS Query

Sub Rule

Suspicious Network Activity

Suspicious

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Number

srcip

<sip>

Number

dstip

<dip>

Number

srcport

<sport>

Number

dstport

<dport>

Number

protocol

<protname>

Text/String

priority

<severity>

Text/String

message

<subject>

Text/String

N/A

<objecttype>

Text/String

classification

<reason>

Text/String

user

<account>

Text/String

client

<sessiontype>

Text/String

ACPolicy

<policy>

Text/String

inlineresult

<status>

Text/String

N/A

<tag1>

Text/String