Hub
Network

Network DNS Traffic

Passive DNS transaction logs — query/response pairs for A, AAAA, CNAME, MX, TXT, PTR, SRV, SOA, NS, and DNSKEY records. Mixed internal/external resolvers with NXDOMAIN, SERVFAIL, and REFUSED errors.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/network-dns/generator.yml \
  --id dns \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
AIPv4 address lookup~60%network
AAAAIPv6 address lookup~16%network
PTRReverse DNS lookup~8%network
CNAMEAlias resolution with CDN chains~4%network
HTTPSSVCB/HTTPS service binding~3%network
TXTSPF/DKIM/DMARC records~3%network
MXMail exchange lookup~2%network
SRVService location (AD, SIP)~2%network
NSNameserver delegation~1%network
SOAZone authority info~0.6%network

Realism Features

  • Weighted query type distribution matching typical enterprise DNS traffic
  • Mixed internal/external domains per template (e.g. 35% internal for A records, 90% for SRV)
  • Response code distribution — ~86% NOERROR, ~10% NXDOMAIN, ~3% SERVFAIL, ~1% REFUSED
  • Realistic answer data — CNAME chains, MX priorities, SRV records for Active Directory services
  • 40 real-world external domains and 30 internal service hostnames
  • Transport variation — UDP (~97%) vs TCP (~3%), higher TCP for TXT and SOA queries

Sample Output

{
    "@timestamp": "2026-02-21T12:00:01.234567+00:00",
    "dns": {
        "answers": [{ "data": "142.250.80.4", "name": "www.google.com", "type": "A" }],
        "question": { "name": "www.google.com", "type": "A" },
        "response_code": "NOERROR",
        "type": "answer"
    },
    "event": {
        "category": ["network"],
        "dataset": "network_traffic.dns",
        "kind": "event"
    },
    "network": { "protocol": "dns", "transport": "udp" }
}

Parameters

ParameterDefaultDescription
hostnameSENSOR01Packetbeat sensor hostname
dns_server_ip10.0.0.10Monitored DNS server IP
internal_domaincontoso.localInternal domain suffix
agent_idb59c76de-...Packetbeat agent ID
agent_version8.17.0Packetbeat version

Related Generators