Sysmon DNS Query Logs - QueryResults Field

1357A 0 Reputation points

How do I display type: 1 for Type A DNS logs in the QueryResults field of Sysmon Event ID 22 DNS Query logs? I tried generating the logs using the below XML format:

<Sysmon schemaversion="4.90">  
    <DnsQuery onmatch="exclude" />  

But when I generate Type A DNS logs, the QueryResults field displays as:


instead of

QueryResults: type: 1;;;

Here are the images of the logs generated for reference:


Sysmon Dns Query logs

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,576 questions
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,724 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,747 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,105 questions
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,082 questions
0 comments No comments
{count} votes