Security Compliance

Integrate Windows DNS server Logs with SEM

This article provides steps to configure Windows DNS to log its debugging traffic, and to configure the Windows DNS Traffic Log connector on the associated SEM Agent.

First published date

10/9/2018 9:07 PM

Last published date

10/9/2018 9:07 PM

Overview

This article applies to Security Event Manager (formerly Log & Event Manager).
This article provides steps to configure Windows DNS to log its debugging traffic, and to configure the Windows DNS Traffic Log connector on the associated SEM Agent.

Product section

Security Event Manager

Resolution

Pre-requisite: SEM agent must be installed on your DNS server. For information see Install the SEM Agent on Windows

Configure Windows DNS to log its debugging traffic (optional) 

  1. Log in to your DNS server as an administrator.

  2. Click Start > Control Panel > Administrative Tools > DNS.

  3. Select your DNS server in the left pane, and then click Actions > Properties.

  4. Click the Debug Logging tab.

  5. Select Log packets for debugging, and then click OK.


Configure the Windows DNS Traffic Log connector on a SEM agent ( Legacy Flash version)

  1. Go to the SEM Console.

  2. Click Manage > Appliances view.

  3. Log in to the SEM Manager as an administrator.

  4. Click Manage, and then select Nodes.

  5. Click the gear icon next to the SEM Agent associated with your DNS server, and then select Connectors.

  6. In the Connector Configuration window, enter DNS Traffic in the search box at the top of the Refine Results field.

  7. Click the gear icon next to the Windows DNS Traffic Log connector, and then select New.

  8. Replace the alias value with a custom alias, or accept the default value, and then click Save.

  9. Click the gear icon next to the new connector, denoted by an icon in the Status column, and then select Start.

  10. Click Close. 

Configure the Windows DNS Traffic Log connector on a SEM agent (HFMTL 5 SEM ver 6.6 and above )

  1. In the SEM Events Console, click the Nodes tab.

  2. Under Refine Results, expand the Type group, and then select the Agent check box.

  3. Select the agent node associated with your DNS server, and then click Manage node connectors.

  4. In the search box, enter DNS traffic.

  5. Select the Windows DNS Traffic Log connector, and then click Add connector.

  6. Replace the name with a custom name, or accept the default value, and then click Add.

  7. Under Configured connectors, select your connector, and then click Start.

When the connector is running, create a filter to display all DNS traffic from that server. For example, use the filter conditions, Any Alert.ToolAlias = *DNS Traffic*, provided you used the default Alias of Windows DNS Traffic Log for your connector.

Configuration to collect the Windows DNS Analytical Log via SEM agent 
1. Login to the Windows DNS Server Where Analytical logs are generated  >  Open Registry Editor > Add a New Key named "Microsoft-Windows-DNSServer/Analytical" under Event Log path > Also Add the File String as shown below
image.png

2. Verify in Event Viewer the registry settings are updated to look like(you may have to re-open event viewer to see changes)
image.png

3. Check the properties of the above Event log file and make sure the file path matches the physical path.
image.png

4. Add the Microsoft-Windows-DNSServer/Analytical Connector Config in SEM web console > Nodes as show below on the DNS server agent node
image.png
5. From SEM web console > Historical Search Search for Events in SEM web console. If all is well, you should see some bars based for DNS Analytical event logs based on raw logs on your DNS server event logs.
image.png

Note: Incase you see SEM Internal Event Warnings Like below, a reboot of DNS server is required to resolve:
image.png