Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (2024)

Table of Contents
Validation What Next?! References

DNS is one of the most powerful data sources to ingest into Splunk for analytics, to fulfil security or IT operations use cases, or even for insights into the operations of your business. Just ask Ryan Kovar—if you're only to choose one data source to put into Splunk, make it your DNS data.

Doing so is not always easy, particularly in a Microsoft Windows environment, and (let’s be honest) it’s highly likely that's what you run. Enabling DNS Debug mode is an option, but it incurs load on the servers and produces a dataset that needs a lot of work to present well in Splunk.

The newly published Splunk Essentials For Wire Data app showcases dozens of use cases that can be applied in your organisation based around wire data. One of the categories within this app is Network Resolution Analysis, which primarily focusses on DNS data. Examples included in the app are:

  • Misconfigured DNS endpoints
  • Detecting IOC’s through DNS
  • Detecting Dynamic DNS domains
  • Detecting domain spoofing
  • Resolution of sites outside the top 1 million

Each of these examples highlights the value of capturing DNS data using Splunk Stream in your environment and its relevance to security and IT operations use cases.

So how do you make this magic happen? Let’s take a step-by-step run through the required configuration, shall we? We'll assume that you have a functioning Splunk environment and have the Splunk Stream app installed. If not, go check out “Installing and Managing Splunk Stream in a Distributed Environment" first for a step-by-step guide on installing Splunk in a distributed environment.

Within the Splunk Stream app, selectConfiguration > Configure Streams.

Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (1)

TheConfigure Streamsdashboard will display the default settings for protocol information to be collected.

Create a new stream for collecting the DNS details that you'd like to capture. Start by selecting theNew Streambutton, thenMetadata Stream.

Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (2)

This will bring you into a workflow that allows you to configure the stream.

SelectDNSas the protocol in the first step.

Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (3)

OnceDNSis selected, give it a name and description with some context to help you to identify the data. ClickNext.

Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (4)

On the aggregation step, ensure thatNois selected for aggregation, then clickNext.(You don't want aggregation because you want to see the individual DNS records.)

Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (5)

On theFieldsscreen, you'll select the fields (specific to DNS) that you want to collect and store in Splunk. Note that some, but not all, fields are selected by default.

Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (6)

Once you've selected the DNS fields that you'd like to collect, clickNext.

You define filtering of the collected data on theFiltersscreen. The filters are based on the fields you selected on the previous screen. For instance, if you only wanted Stream to capture data from type "A" queries, you could define that here.

Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (7)

Filters are something that you may want to go back and tweak later, once you've collected data for a while and know what you have and what you'd like to keep (or discard).

Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (8)

After defining filters, select theNextbutton again to go to theSettingsscreen, where you'll define the destination index for your DNS data.

Select the destination index from the dropdown menu. You can set a custom index here, after creating it under settings->indexes.

Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (9)

After selecting the destination index, you can choose to save the configuration inDisabledmode if you're not quite ready to begin collecting data. You can also put it intoEstimatemode to get an idea of how much data you'll be collecting once the configuration is enabled.

Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (10)

On theGroupsscreen, here is where you have a decision to make—you'll have the ability to select a group with which to associate the Stream configuration.

Your first option is to deploy to only the Windows DNS servers in your environment. If doing so, ensure you have the Splunk Universal Forwarder deployed to those hosts and create a Stream Group containing those servers. This option will capture client and server-side requests and responses. This can be done without touching any of your actual endpoints and will provide you with all DNS resolution data from your environment.

Your second option—if you're wanting to collect DNS data from distributed forwarders being your endpoint machines without touching the DNS server infrastructure at all, create a new group and add your forwarders to it. This option will allow you to see the client-side DNS requests and responses. You won’t see the requests generated by the DNS servers in your environment or any endpoints that don’t have a UF on them.

There are other options and architectures available to you using Splunk Stream, but we will cover those off in subsequent blog posts. These include using a Stream forwarder receiving traffic from a network TAP or SPAN port, or leveraging Stream’s ability to capture netflow or sflow data.

Finally, clickCreate Streamto save your configuration. You're done!

Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (11)

Validation

If you've enabled the configuration, you should now be collecting DNS data. You can validate this by searching for:

sourcetype=stream:dns

You should able to see beautiful JSON blobs of DNS transactions, with fields available on the left.

Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (12)

Remember that Splunk offers a reduced-cost license to ingest your DNS data (netflow, too!), which you can read more abouthere. This license allows you to ingest an individual sourcetype (DNS in our case) at a lower per GB cost than your normal Splunk Enterprise license.

What Next?!

Why not head over to Splunkbase and download the new Splunk Essentials for Wire Data app, which showcases 49 example use cases, across security, IT ops and fraud, all using data solely from Splunk Stream. Grab it here.

Credit to Steve Brant and David Veuve for creating much of this content, which is also available in the Splunk Security Essentials app Data Onboarding Guides.

Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (13)

Simon O'Brien

I am a passionate Splunker, traveller, family man, cook, basketballer, social advocate and security professional. I have the best job in the world, and live in the best place in the world.

Splunking DNS Using Splunk Stream – AKA, The Easy Way | Splunk (2024)

References

Top Articles
بهترین فیلم های عاشقانه جهان؛ 43 پیشنهاد
فیلم عاشقانه ۲۰۲۲ ؛ معرفی 27 عنوان از جدیدترین فیلمهای عاشقانه 2022
Lakers Game Summary
Jonathon Kinchen Net Worth
³µ¿Â«»ÍÀÇ Ã¢½ÃÀÚ À̸¸±¸ ¸íÀÎ, ¹Ì±¹ Ķ¸®Æ÷´Ï¾Æ ÁøÃâ - ¿ù°£ÆÄ¿öÄÚ¸®¾Æ
سریال رویای شیرین جوانی قسمت 338
2022 Apple Trade P36
Best Cheap Action Camera
Decaying Brackenhide Blanket
What's New on Hulu in October 2023
Visustella Battle Core
Bustle Daily Horoscope
Remnant Graveyard Elf
Identogo Brunswick Ga
Wizard Build Season 28
9044906381
Plan Z - Nazi Shipbuilding Plans
How pharmacies can help
Odfl4Us Driver Login
Copart Atlanta South Ga
Craigslist Personals Jonesboro
Maxpreps Field Hockey
Jail View Sumter
Gotcha Rva 2022
Craigslist Roseburg Oregon Free Stuff
Horn Rank
Trivago Myrtle Beach Hotels
55Th And Kedzie Elite Staffing
1979 Ford F350 For Sale Craigslist
Restaurants In Shelby Montana
Maine Racer Swap And Sell
Meijer Deli Trays Brochure
27 Fantastic Things to do in Lynchburg, Virginia - Happy To Be Virginia
Cinema | Düsseldorfer Filmkunstkinos
Die wichtigsten E-Nummern
DIY Building Plans for a Picnic Table
+18886727547
Ni Hao Kai Lan Rule 34
Unity Webgl Player Drift Hunters
ATM Near Me | Find The Nearest ATM Location | ATM Locator NL
8005607994
Hell's Kitchen Valley Center Photos Menu
Craigslist Pets Plattsburgh Ny
The Angel Next Door Spoils Me Rotten Gogoanime
Joey Gentile Lpsg
How Much Is 10000 Nickels
Tableaux, mobilier et objets d'art
Interminable Rooms
Vagicaine Walgreens
Julies Freebies Instant Win
Denys Davydov - Wikitia
Lorcin 380 10 Round Clip
Latest Posts
Article information

Author: Pres. Lawanda Wiegand

Last Updated:

Views: 5487

Rating: 4 / 5 (51 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Pres. Lawanda Wiegand

Birthday: 1993-01-10

Address: Suite 391 6963 Ullrich Shore, Bellefort, WI 01350-7893

Phone: +6806610432415

Job: Dynamic Manufacturing Assistant

Hobby: amateur radio, Taekwondo, Wood carving, Parkour, Skateboarding, Running, Rafting

Introduction: My name is Pres. Lawanda Wiegand, I am a inquisitive, helpful, glamorous, cheerful, open, clever, innocent person who loves writing and wants to share my knowledge and understanding with you.