Forum Discussion

AndrewX's avatar
AndrewX
Iron Contributor
Jun 01, 2019

OMS DNS Analytics solution - no data

Hello - I am trying to get DNS logs into Log Analytics and into Sentinel.

 

The Documentation here (https://docs.microsoft.com/en-us/azure/sentinel/connect-dns), says simply install OMS and check the DnsEvent table, i did, nothing's there..  PS.  It's been many days, and nothing is there.

 

  • Although the documentation does not specify, but does DNS diagnostic logging need to be enabled for this to work?
  • And if so, does that mean a custom log and data collection need to be configured for \path\to\dns.log?

 

Side Note:  I have packetbeat installed successfully capturing DNS logs without DNS Diagnostic Logging enabled.

 

11 Replies

Resources