Security Compliance
DNS analytical data is not received in SEM
This article provides additional steps to get the Windows DNS Server - Analytical connector to function properly on a Windows node.
First published date
Last published date
Overview
For the Windows DNS Server - Analytical connector to function properly on a Windows node, some additional steps - provided below - are required.
Product section
Resolution
Follow the steps below to set up registry entries and add a registry key:
-
Make sure DNS manager debug logs are on (optional)
-
Create Microsoft-Windows-DNSServer-Analytical (with -) key in RegistryEditor on path: Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog
-
Right-click on key -> New -> Expandable String value, name it File (Please check if a File TYPE is REG_EXPAND_SZ otherwise it wont work)
-
Double click on this newly created value, and set value data to %SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-DNSServer-Analytical.etl
-
Go to Event Viewer, Application and Services Logs -> Microsoft -> Windows -> DNS Server.
-
Right-click on Analytical -> Properties > Uncheck "Enable logging" > Make sure to click Apply after each change. Press Apply
-
Set Log path to %SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-DNSServer-Analytical.etl and Apply again**
-
Check Do not overwrite events (optional).
-
Check enable logging again, Apply. Close and open properties again and make sure logging is enabled and log path is set properly (Full name does not matter)
-
Set Analytical Connector in SEM web console with Microsoft-Windows-DNSServer-Analytical option.
-
SEM should start to receive events.
Warning: SolarWinds strongly recommends that you back up (File > Export) your registry before making any edits to your system registry. You should only edit the registry if you are experienced and confident in doing so. Using a registry editor incorrectly can cause serious issues with your operating system, which could require you to reinstall your operating system to correct them. SolarWinds cannot guarantee resolutions to any damage resulting from making registry edits.