Skip to content

Add DNS Event Support #16

@cthulhusec

Description

@cthulhusec

Add DNS events to the Security Events schema and the mapping for Sysmon conversion.

Field mappings

query_name = "QueryName"
query_results = "QueryResults"
query_status = "QueryStatus"

I think the rest should be generic fields already mapped.

Metadata

Metadata

Assignees

No one assigned

    Labels

    good first issueGood for newcomersschemaAdd a field to the schema or a data source

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions