Azure Setinel Lookup queries logs

Eduards 791 Reputation points
2021-01-03T09:45:37.403+00:00

Hello,

I configuret Azure Sentinel Workspace.

Installed MMA agent on DNS server and enabled DNS logging. And added DNS log event to workspace configuratian.

I am receiving logs about DNS dynamic updates but don't get Lookup Query logs.

DNS debug logging is enabled.

What could be the couse?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
996 questions
0 comments No comments
{count} votes

Accepted answer
  1. Russell Graham 156 Reputation points
    2021-01-03T09:57:51.363+00:00

    You need to enable DNS Analytic Event logging to get the lookup queries as it's not enabled by default, refer dn800669(v=ws.11) . Be aware of the performance impact on the DNS server to have both Audit and Analytic event logging enabled


1 additional answer

Sort by: Most helpful
  1. Eduards 791 Reputation points
    2021-01-05T09:47:31.377+00:00

    After enablign analytic DNs loggin i see records in DNS event viewer but this data is not trasnferred to Azure Setninel.. @Russell Graham

    0 comments No comments