Skip to main content
Skip table of contents

V 2.0 : DNS Logs

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 : DNS LogsBase RuleGeneral DNS InformationInformation
V 2.0 : DNS Traffic AllowedSub RuleTraffic Allowed by Network FirewallNetwork Allow
V 2.0 : DNS Traffic BlockedSub RuleTraffic Denied by Network FirewallNetwork Deny

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

TimestampN/AN/AWhen this request was made in UTC. This is different than the Umbrella dashboard, which converts the time to your specified time zone
Most Granular Identity N/AN/AThe first identity matched with this request in order of granularity.
Identities<object>Text/StringAll identities associated with this request.
Internal IP<sip>IP AddressThe internal IP address that made the request.
External IPN/AN/AThe external IP address that made the request.
Action

<action>

<tag1>

Text/StringWhether the request was allowed or blocked.
Query Type N/AN/AThe type of DNS request that was made. For more information, see Common DNS Request Types.
Response Code<responsecode>NumberThe DNS return code for this request. For more information, see Common DNS return codes for any DNS service (and Umbrella).
Domain<domainimpacted>Text/StringThe domain that was requested.
Categories<subject>Text/StringThe security or content categories that the destination matches. For category definitions, see Understanding Security Categories and Understanding Content Categories.
Most Granular Identity TypeN/AN/AThe first identity type matched with this request in order of granularity. Available in version 3 and above.
Identity Types<objecttype>Text/StringThe type of identity that made the request. For example, Roaming Computer, Network, and so on. Available in version 3 and above.
Blocked CategoriesN/AN/AThe categories that resulted in the destination being blocked. Available in version 4 and above.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.