Genian EDR

Download 29
Last updated Aug 6, 2023

DNS Log

Normalize DNS logs in Genian EDR.

TypeFieldDisplay Name
DATE_timeTime
STRINGevent_typeEvent type
STRINGevent_subtypeEvent subtype
INTimportantImportant level
IPhost_ipHost IP
STRINGnt_domainNT domain
STRINGhostnameHostname
STRINGtagTag
STRINGimageProcess name
STRINGdns_queryDNS query
STRINGdns_answerDNS answer
STRINGimage_pathProcess path
STRINGdirectionDirection
IPlocal_ipLocal IP
INTlocal_portLocal port
IPremote_ipRemote IP
INTremote_portRemote port
STRINGprotocolProtocol
INTis_connectedIs connected
STRINGlogon_idLogon ID
INTpidPID
STRINGpguidProcess GUID
STRINGdevice_idDevice ID
LONGevent_seqEvent sequence
STRINGinfo_titleInfo title
STRINGinfoInfo details