Windows 10: Sysmon DNS Query Support

Discus and support Sysmon DNS Query Support in Windows 10 Gaming to solve the problem; I have been trying to generate Sysmon Event ID 22 DNS Query logs using the below xml format <Sysmon schemaversion="4.90"> <EventFiltering> <DnsQuery... Discussion in 'Windows 10 Gaming' started by 1357A, Mar 8, 2024.

  1. 1357A Win User

    Sysmon DNS Query Support


    I have been trying to generate Sysmon Event ID 22 DNS Query logs using the below xml format <Sysmon schemaversion="4.90"> <EventFiltering> <DnsQuery onmatch="exclude" /> </EventFiltering> </Sysmon> But type: 1 is not displayed for logs when I try to generate Type A DNS logs. Why is it displaying QueryResults field as QueryResults: 52.206.163.162;34.234.52.18;3.233.126.24; and not QueryResults: type: 1 52.206.163.162;34.234.52.18;3.233.126.24; ?

    :)
     
    1357A, Mar 8, 2024
    #1
  2. 1357A Win User
    1357A, Mar 8, 2024
    #2
  3. 1357A Win User
    Sysmon DNS Query Support

    I have been trying to generate Sysmon Event ID 22 DNS Query logs using the below xml format

    <Sysmon schemaversion="4.90">

    <EventFiltering>

    <DnsQuery onmatch="exclude" />

    </EventFiltering>

    </Sysmon>

    But I am only able to see logs with QueryResults: type: 5 and not any other number in place of 5. Example values like type: 1, type: 2, type: 3 etc.. How do I generate logs with different numbers for type field in QueryResults? Can you let me know the xml format that can be used to generate them?


    Sysmon DNS Query Support vD1lUAiJxEm%2FizEMKObWY0sgtDU8kkvdm0F1zIeUn%2F1a5SUUuvT1OTQI4lnmCYy9Prgpb3QhgOvmIVDJteaP8LQec%3D.png
     
    1357A, Mar 8, 2024
    #3
  4. 1357A Win User

    Sysmon DNS Query Support

    Sysmon DNS Query Support

    Hi,

    Is there any other way that I can contact Sysmon support? Any Email or other mode of contact other than the Q&A forum?
     
    1357A, Mar 8, 2024
    #4
Thema:

Sysmon DNS Query Support

Loading...
  1. Sysmon DNS Query Support - Similar Threads - Sysmon DNS Query

  2. Sysmon DNS Query Support

    in Windows 10 Software and Apps
    Sysmon DNS Query Support: I have been trying to generate Sysmon Event ID 22 DNS Query logs using the below xml format <Sysmon schemaversion="4.90"> <EventFiltering> <DnsQuery onmatch="exclude" /> </EventFiltering> </Sysmon> But type: 1 is not displayed for logs when I try to generate Type A DNS...
  3. Sysmon DNS Query Support

    in Windows 10 Gaming
    Sysmon DNS Query Support: I have been trying to generate Sysmon Event ID 22 DNS Query logs using the below xml format <Sysmon schemaversion="4.90"> <EventFiltering> <DnsQuery onmatch="exclude" /> </EventFiltering> </Sysmon>But I am only able to see logs with QueryResults: type: 5 and not any other...
  4. Sysmon DNS Query Support

    in Windows 10 Network and Sharing
    Sysmon DNS Query Support: I have been trying to generate Sysmon Event ID 22 DNS Query logs using the below xml format <Sysmon schemaversion="4.90"> <EventFiltering> <DnsQuery onmatch="exclude" /> </EventFiltering> </Sysmon>But I am only able to see logs with QueryResults: type: 5 and not any other...
  5. Sysmon DNS Query Support

    in Windows 10 Software and Apps
    Sysmon DNS Query Support: I have been trying to generate Sysmon Event ID 22 DNS Query logs using the below xml format <Sysmon schemaversion="4.90"> <EventFiltering> <DnsQuery onmatch="exclude" /> </EventFiltering> </Sysmon>But I am only able to see logs with QueryResults: type: 5 and not any other...
  6. Windows DNS Client Not Querying Specified DNS Server Without Connection Specific Suffix

    in Windows 10 Software and Apps
    Windows DNS Client Not Querying Specified DNS Server Without Connection Specific Suffix: We have 3 DCs, all running the DNS role. These servers hold the records for the domain itself but also "external" records using split-horizon DNS. IP Addresses for the servers are all static whereas the clients all have DHCP-assigned addresses.Currently, we are testing a new...
  7. Redirect DNS query based on IP

    in Windows 10 Gaming
    Redirect DNS query based on IP: Hi Everyone,I need help regarding the MS DNS server.I have 3 DNS servers in our organization. There are 2 groups in our environment, one is internal user and other are guest and temporary users.Is there a way we can resolve queries based on IP. For example internal user...
  8. Redirect DNS query based on IP

    in Windows 10 Software and Apps
    Redirect DNS query based on IP: Hi Everyone,I need help regarding the MS DNS server.I have 3 DNS servers in our organization. There are 2 groups in our environment, one is internal user and other are guest and temporary users.Is there a way we can resolve queries based on IP. For example internal user...
  9. MSMPENG.EXE - Dns Queries

    in AntiVirus, Firewalls and System Security
    MSMPENG.EXE - Dns Queries: Hi, I am unable to find why in some cases the antimalware (MsMpEng.exe) is doing dns queries (event 22 in sysmon). This does not appear to be consistent. I entered a url in Chrome and Firefox, Sysmon event log showed that these processes were reaching out (through dns...
  10. Sysmon update introduces DNS Query Logging

    in Windows 10 News
    Sysmon update introduces DNS Query Logging: A new version of the Sysmon tool will be released on Tuesday 11, 2019 that introduces DNS query logging to the Windows system monitor. Mike Russinovich, the creator of the tool and Microsoft Azure CTO, teased the new feature in a message on Twitter on June 8, 2019. The...