Sysmon DNS Query Logs - QueryResults Field

1357A 0 Reputation points
2024-03-11T04:05:38.8966667+00:00

How do I display type: 1 for Type A DNS logs in the QueryResults field of Sysmon Event ID 22 DNS Query logs? I tried generating the logs using the below XML format:

<Sysmon schemaversion="4.90">  
<EventFiltering>  
    <DnsQuery onmatch="exclude" />  
</EventFiltering>  
</Sysmon>

But when I generate Type A DNS logs, the QueryResults field displays as:

QueryResults: 52.206.163.162;34.234.52.18;3.233.126.24;

instead of

QueryResults: type: 1 52.206.163.162;34.234.52.18;3.233.126.24;

Here are the images of the logs generated for reference:

1

Sysmon Dns Query logs

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,946 questions
Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,935 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,807 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,620 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,112 questions
0 comments No comments
{count} votes