To conduct a federated search for domain names, you must add the DNS Request
Domain custom event property to the appropriate DSMs in IBM® QRadar. The DNS Request Domain
custom event property parses the DNS Request Domain for a log source type.
About this task
You must have the administrator role to add the DNS Request Domain
custom event to your
DSMs.
Procedure
-
Log in to QRadar® as an administrator.
-
From the Admin tab, click DSM Editor.
-
In the Select Log Source Type window, click the log source type that you
want to edit, and then click Select.
-
On the Properties tab, click the Add icon
(+).
-
In the Choose a Custom Property Definition window, select DNS
Request Domain, and then click Select.
- If the DNS Request Domain custom event property is not listed,
follow these steps to create it.
- In the Choose a Custom Property Definition window, click
Create New.
- In the Name field, enter DNS Request
Domain.
- In the Field Type field, select
Text.
- In the Description field, enter a description and then select
the Enable for use in Rules, Forwarding Profiles and Search Indexing
checkbox.
- Click Save and then click
Select.
-
On the Properties tab, click the DNS Request
Domain custom event property. If the DNS Request Domain custom
event property was listed in the Choose a Custom Property Definition window,
click Edit.
-
Ensure that the Expression Type is Regex.
-
In the Expression field, enter Question
Name=(\S+).
Restriction: The Question Name=(\S+) regular expression (regex)
applies only to the DNS Request Domain custom event property.
-
In the Capture Group field, enter 1.
-
To confirm the edit, click OK, and then click
Save to update the DSM.
Results
If the DNS Request Domain custom event property is added to your DSM,
a green checkmark is displayed, and the custom event property is listed on the
Properties tab.