DNS Process Plugin
The DNS process plugin provides the domain name assigned to an IP address and the other way around. The plugin takes any number of inputs (IP addresses or hostname) and an equal number of aliases to store the output. For any input provided, the plugin first verifies the value of the field. If the value is an IP address, it resolves the address to its hostname. Otherwise, it resolves the value to an IP address.
Package Details
Important Notice
The DNS process application takes a longer time to execute the process command for the unresolved IP Addresses.
Bug Fixes
-
Previously, the application did not resolve some IP addresses (spoofed IPs) to their corresponding hostnames. This has been fixed.
- The application now highlights enriched fields in the participating logs while using the join query in the process command.
Usage Information
Syntax: | process dns(IP Address or Hostname)
For example, "| process dns(destination_address)" command resolves the destination_address field value to the hostname.
Sample Log
Installation
Follow these steps to install the DNS Process Plugin v3.1.0:
- Download the DNS Process Plugin package provided above in the Download section.
- Install the package by importing the pak file to LogPoint under Settings >> System >> Applications.
Package Details
Important Notice
It takes a longer time for the plugin to execute the process command for the unresolved IP Addresses.
Bug Fixes
-
Previously, the plugin did not resolve some IP addresses (spoofed IPs) to their corresponding hostnames. This has been fixed.
- The plugin now highlights enriched fields in the participating logs while using the join query in the process command.
Usage Information
General Syntax: | process dns(<IP Address or Hostname>) as <attribute_name>
For example, the "| process dns(ip) as domain_name" command resolves the ip field value to the hostname and stores the hostname to the domain_name field.
Installation
Follow these steps to install the DNS Process Plugin v3.1.0:
- Download the DNS Process Plugin package provided above in the Download section.
- Install the package by importing the pak file to LogPoint under Settings >> System >> Applications.
Support
If you have any queries or require assistance, please feel free to contact our support team:
Email: servicedesk@logpoint.com
Phone: +45 7060 6100
Best regards,
Comments
Please sign in to leave a comment.