Skip to main content
Skip table of contents

V 2.0 : DNS Logs

Vendor Documentation


Rule NameRule TypeCommon EventClassification
V 2.0: DNS LogsBase RuleGeneral DNS InformationInformation
V 2.0: DNS Traffic AllowedSub RuleTraffic Allowed by Network FirewallNetwork Allow
V 2.0: DNS Traffic BlockedSub RuleTraffic Denied by Network FirewallNetwork Deny

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Text/StringWhether the request was allowed or blocked.
Blocked Categories<result>Text/StringThe categories that resulted in the destination being blocked. Available in version 4 and above.
Categories<subject>Text/StringThe security or content categories that the destination matches. For category definitions, see Understanding Security Categories and Understanding Content Categories.
Domain<domainimpacted>Text/StringThe domain that was requested.
External IP<dip>IP AddressThe external IP address that made the request.
Text/StringAll identities associated with this request.
Identity Types<objecttype>Text/StringThe type of identity that made the request. For example, Roaming Computer, Network, and so on. Available in version 3 and above.
Internal IP<sip>IP AddressThe internal IP address that made the request.
Most Granular Identity N/AN/AThe first identity matched with this request in order of granularity.
Most Granular Identity TypeN/AN/AThe first identity type matched with this request in order of granularity. Available in version 3 and above.
Query Type N/AN/AThe type of DNS request that was made. For more information, see Common DNS Request Types.
Response Code<responsecode>NumberThe DNS return code for this request. For more information, see Common DNS return codes for any DNS service (and Umbrella).
TimestampN/AN/AWhen this request was made in UTC. This is different from the Umbrella dashboard, which converts the time to your specified time zone
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.