Microsoft DNS
You can integrate Microsoft DNS servers with Sophos XDR so that they send data to Sophos for analysis.
This page gives you an overview of the integration.
Microsoft DNS servers overview
Microsoft DNS Server is the DNS role in Windows Server that resolves domain names to IP addresses and stores and replicates DNS zones. It's a core component of Active Directory Domain Services, used to locate domain controllers, and supports dynamic updates, DNSSEC, forwarding, caching, and query logging.
What we ingest
A Sophos XDR data collector accepts Microsoft DNS debug logs in the Snare-over-syslog format, forwarded from your Windows DNS servers by Snare or NXLog. The following log categories are collected:
- DNS activity: Windows DNS server query and response events from the DNS debug log.
Event and data types
We ingest the following event and data types from Microsoft DNS servers:
- DNS activity: Windows DNS server query and response events from the DNS debug log, including the queried domain, record type, client, and response. Normalized to DNS query telemetry.
Data provided by this integration
Data provided by Microsoft DNS servers gets normalized to the following schemas:
dnsquery
For more information about using schemas in Data Lake Search, see Schemas and logical types.