Microsoft DNS 디버그 샘플 이벤트 메시지
이 샘플 이벤트 메시지를 사용하여 IBM QRadar와의 성공적인 통합을 확인하십시오.
중요: 형식화 문제로 인해 메시지 형식을 텍스트 편집기에 붙여넣은 후 캐리지 리턴 또는 줄 바꾸기 문자를 제거하십시오.
Syslog 프로토콜을 사용할 때 Microsoft DNS 디버그 샘플 메시지
다음 샘플 이벤트는 DNS 유형 A 조회를 표시합니다.
<13>Aug 01 07:46:17 microsoft.dns.test AgentDevice=WindowsDNS AgentLogFile=dns.log PluginVersion=192.168.63.93 Date=1/08/2019 Time=7:46:13 Thread ID=a.m. 0E40 Context=PACKET Message= Internal packet identifier=000000A018724240 UDP/TCP indicator=UDP Send/Receive indicator=Snd Remote IP=192.168.113.142 Xid (hex)=0f5f Query/Response=Q Opcode=Q Flags (hex)=0001 Flags (char codes)=D ResponseCode=NOERROR Question Type=A Question Name=d3hb14vkzrxvla.cloudfront.net
| QRadar 필드 이름 | 페이로드에서 강조표시된 값 |
|---|---|
| 이벤트 ID | 유형 |
| 카테고리 | WindowsDNS |
| 대상 주소 | 원격 IP |
| 로그 소스 시간 | 8월 1일 07:46:17 |