BIND 9 Query Log
ISC BIND 9.18 queries category records from one recursive resolver serving 24 internal clients (4 servers and 20 workstations), as native named query-log lines in event.original with ECS fields parsed from them, for DNS monitoring and DNS-exfiltration detection testing. About 12,900 queries a day: servers query around the clock, workstations follow nine-hour working shifts in UTC. Recurring episodes show one workstation sending eight TXT queries with distinct high-entropy labels to one tunnel zone within a few minutes.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/network-bind9-query/generator.yml \
--id bind9 \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| A | Host lookups under example.com, example.net, example.org, plus the mail host after an MX | 43.8% of queries | network |
| AAAA | IPv6 lookups, usually right after the matching A | 22.0% of queries | network |
| TXT on analytics zones | Workstation runs of high-entropy labels under metrics.example.net / insights.example.org | 13.8% of queries | network |
| PTR | Reverse lookups in 10.in-addr.arpa, mostly from servers | 7.9% of queries | network |
| MX | Mail-exchanger lookups by servers | 4.8% of queries | network |
| TXT on tunnel zones | Short workstation runs of high-entropy labels under the tunnel zones, plus the anomaly episodes | 3.5% of queries | network |
| TXT DKIM / DMARC | <selector>._domainkey.<domain> and _dmarc.<domain> lookups by servers | 3.1% of queries | network |
| A / AAAA / NS on tunnel-zone apex | Workstation lookups of the tunnel zones themselves | 1.2% of queries | network |
Realism Features
- One recursive resolver serves 4 servers and 20 workstations, about 12,900 queries a day, each day's volume varying by up to 3%. Workstations work nine-hour shifts in UTC (a quarter 07:00-16:00, half 08:00-17:00, a quarter 09:00-18:00) and send 900 queries an hour with every shift in, about 45 per workstation; about 30% of them stay switched on overnight and send 50 queries an hour between them. Servers send 150 queries an hour around the clock. Each hour holds about 1.5% of the day's queries at night, 3.3% at 07:00 and 17:00, 6.8% at 08:00 and 16:00 and about 8.5% from 09:00 to 16:00.
- Servers make the MX, DKIM / DMARC and most PTR lookups; workstations make the high-entropy TXT runs to the analytics and tunnel zones and the tunnel-zone apex lookups. The traffic mix is a synthetic assumption, not measured resolver traffic.
- In both modes every workstation sends high-entropy TXT queries to both tunnel zones in short runs (1-2 queries typical), from a few to about 30 times a day per zone, and looks up the zone apex. A client reaches seven TXT queries to one tunnel zone within an hour about 7-13 times a day, but outside episodes never eight. Runs of 8 or more high-entropy TXT queries from one client to one analytics zone within an hour occur about 80-100 times a day.
- Flags follow the BIND order: recursion (+/-), E(0), T, D, then cookie V or K. About 90% of queries carry EDNS and about 3% arrive over TCP; DO and the cookie flags appear only together with E(0).
- Queries that belong together (an A and its AAAA, an MX and the mail host lookup, the queries of a run) are seconds apart rather than milliseconds: an AAAA follows its A after a median of 3.5 seconds. Every day follows the same working-day curve in UTC; weekends, holidays and local time zones are not modelled, and shifts start exactly on the hour.
- The native line follows the BIND 9.18 source code and assumes a file channel with print-time iso8601-utc, print-category and print-severity. The ARM publishes only the message part, so the prefix is taken from the source code, not from a published capture; other channel settings change the prefix, and syslog adds its own header.
- Only the default view is modelled. Signed queries, CD, EDNS Client Subnet and IPv6 clients are not generated, the client object is a random pointer-like value per query without reuse, and dns.question.registered_domain holds the delegated service zone, not the public-suffix registered domain.
- Query logs contain no responses or answer data, so a rule of 8 or more TXT queries with distinct long labels from one client to one watched zone within an hour shows the pattern, not that data was actually transferred. Traffic mix, shifts, rates and episode shape are synthetic.
Sample Output
{
"@timestamp": "2026-09-01T17:21:39.576000+00:00",
"bind9": {
"query": {
"client_object": "@0x7fff9ced1927",
"flags": "+E(0)K"
}
},
"destination": {
"ip": "10.20.30.53",
"port": 53
},
"dns": {
"question": {
"class": "IN",
"name": "bcc9a59a2f23b1879b033c138a3cac4f5746.sync.example.test",
"registered_domain": "sync.example.test",
"type": "TXT"
},
"type": "query"
},
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "dns-query",
"category": [
"network"
],
"dataset": "bind9.query",
"kind": "event",
"original": "2026-09-01T17:21:39.576Z queries: info: client @0x7fff9ced1927 10.20.40.33#1195 (bcc9a59a2f23b1879b033c138a3cac4f5746.sync.example.test): query: bcc9a59a2f23b1879b033c138a3cac4f5746.sync.example.test IN TXT +E(0)K (10.20.30.53)",
"type": [
"protocol",
"info"
]
},
"host": {
"name": "ns1.example.test"
},
"network": {
"protocol": "dns",
"transport": "udp"
},
"observer": {
"hostname": "ns1.example.test",
"product": "BIND",
"type": "dns",
"vendor": "ISC"
},
"related": {
"ip": [
"10.20.40.33",
"10.20.30.53"
]
},
"source": {
"ip": "10.20.40.33",
"port": 1195
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add the recurring exfiltration episodes; false produces background traffic only |
| anomaly_interval_hours | 24 | Hours of source time between episodes, counted from the actual start of the previous one, 2 to 8,760 |
| server_name | ns1.example.test | Resolver host name written to host.name and observer.hostname |
| server_ip | 10.20.30.53 | Address the queries arrive on, as it appears in the log line |
| client_prefix | 10.20.40. | First three octets of the client addresses |
| client_first | 11 | Last octet of the first client |
| client_count | 24 | Number of clients, servers included |
| server_count | 4 | How many of the first client addresses are servers; the rest are workstations, at least 4 |
| tunnel_zones | [telemetry.example.test, sync.example.test] | Zones the episodes target, also queried in background, at least 2 |
| analytics_zones | [metrics.example.net, insights.example.org] | Zones that receive long high-entropy TXT runs in background, at least 2 |
Related Generators
Cisco ASA Firewall
Cisco ASA adaptive security appliance syslog — TCP/UDP/ICMP connection lifecycle, ACL permit/deny decisions, NAT translations, VPN tunnel events, and failover status messages.
Check Point Security Gateway
Check Point Security Gateway SmartLog — 8 software blades including Firewall, IPS, Application Control, URL Filtering, Anti-Bot, Anti-Virus, Threat Emulation, and Identity Awareness.
Network Traffic (Continent-Level Geo)
Network traffic events enriched with continent-level geographic information. Models cross-continent and same-continent flows for both inbound and outbound directions, with realistic allow/deny outcomes based on geographic policy.