Sysmon DNS Query Support

1357A 0 Reputation points
2024-01-17T12:14:49.9433333+00:00

I have been trying to generate Sysmon Event ID 22 DNS Query logs using the below xml format  <Sysmon schemaversion="4.90">  <EventFiltering>  <DnsQuery onmatch="exclude" />  </EventFiltering>  </Sysmon> But type: 1 is not displayed for logs when I try to generate Type A DNS logs. Why is it displaying QueryResults field as QueryResults: 52.206.163.162;34.234.52.18;3.233.126.24; and not QueryResults: type: 1 52.206.163.162;34.234.52.18;3.233.126.24;? 1 Sysmon Dns Query logs

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,985 questions
Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,960 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,808 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,665 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,115 questions
0 comments No comments
{count} votes