This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

can´t see DNS Traffic

Hello ,

I have configuered my DC as suggested in whitepapers (audit policy etc),

DNS Server is set on clients to the DC

In LEM i have added DNS connectors (on DC):

windows dns server audit log

windows dns traffic log

on the firewall I have a rule which allows traffic only through our security solution.

in this security solution I see blocked traffic to several "bad" sites with malware, mining and command & control traffic.

And now my problem, I can´t find in LEM this sites. I can also not find sites which I have opened by myself. What have I forgotten to set?

thanks for your help in advance

andy

  • There was a pretty similar post a few days ago where I posted some suggestions to start with if you want to check it out and reply back:

    Tracking DNS traffic

    Assuming the connector configuration isn't the issue, the first thing you'll want to make sure of is the logs have the data.  The majority of the DNS connectors pull from the Event Logs so there's no real LEM-based configuration there and the other is a file path.  If there is data in the logs I have a follow up suggestion, but it would require additional configuration on the client machines.