PowerDNS Authoritative Query Log
PowerDNS Authoritative Server 5.0.1 per-query lines (log-dns-queries, classic unstructured stderr output, packet cache on) as native text in event.original with parsed ECS fields. One server answers for a few zones; four recursive resolvers and a group of directly connected hosts query it over UDP. Recurring episodes show one direct client checking a zone with SOA and NS and then enumerating ten distinct names in it.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/network-powerdns-authoritative/generator.yml \
--id powerdns-auth \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| A | Host lookups, including stale or mistyped names and short inventory sweeps by direct clients | 62.6% measured share | network |
| AAAA | IPv6 host lookups | 18.8% measured share | network |
| MX | Mail-exchanger lookups of a zone apex | 6.7% measured share | network |
| TXT | Zone-apex TXT (SPF) lookups | 5.8% measured share | network |
| NS | Name-server set of a zone apex | 4.0% measured share | network |
| SOA | Serial and zone checks by direct clients; resolvers never ask for SOA in this model | 2.2% measured share | network |
Realism Features
- About 21,000 queries a day, about 340 per hour at 19:00-07:00 UTC, 1,050-1,250 at 07:00-09:00 and 17:00-19:00 and about 1,560 at 09:00-17:00; daily volume varies by about 3%. The traffic mix, rates and client behaviour are synthetic assumptions.
- Four recursive resolvers send about 69% of the queries, each an independent question, so a resolver repeats a name within five minutes more often than a caching resolver would. Directly connected clients send short sessions (repeated single lookups, zone checks, inventory sweeps, mail-routing checks), each with its own weight and daily activity window.
- A question repeated with the same name, type, DO bit and EDNS size within 20 seconds (the default cache-ttl) is a packetcache HIT (5-8% of lines), anything else a MISS. The real cache hashes the whole query packet and also honours shorter answer TTLs.
- EDNS follows the server parser: no EDNS logs do = 0, bufsize = 512; with EDNS the advertised size is clamped to 512-1232 and shown in parentheses when it differs. Resolvers send EDNS with DO set; direct clients use EDNS 1232, EDNS 4096 or none, and dig-like clients occasionally set DO.
- Every episode client also queries SOA, NS, MX, TXT and A for the same zones in ordinary traffic, and zone checks followed by sweeps of several distinct names occur every day. Ordinary traffic reaches SOA, NS and nine distinct names within five minutes but never the tenth; the same sequence over more than five minutes also occurs.
- The line format follows the 5.0.1 source and one complete captured line in a vendor issue, not a recording of a live daemon. The timestamp is the daemon local time, here UTC, with one-second resolution and no syslog or journald wrapper; session queries are seconds apart, often 10 s or more at night, slower than a real dig or script.
- Only UDP queries are modelled: no TCP, PROXY protocol, EDNS Client Subnet, overload drops, structured logging (5.1+) or Recursor. The log records questions only, with no response code or answer.
Sample Output
{
"@timestamp": "2026-09-01T08:56:21+00:00",
"dns": {
"question": {
"name": "vpn2.corp.example",
"registered_domain": "corp.example",
"type": "A"
},
"type": "query"
},
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "dns-query",
"category": [
"network"
],
"kind": "event",
"original": "Sep 01 08:56:21 Remote 10.20.40.21 wants \u0027vpn2.corp.example|A\u0027, do = 0, bufsize = 1232: packetcache MISS",
"type": [
"info"
]
},
"host": {
"name": "ns01.corp.example"
},
"powerdns": {
"dnssec_ok": false,
"edns_buffer_size": 1232,
"packet_cache": "MISS",
"server_type": "authoritative"
},
"related": {
"ip": [
"10.20.40.21"
]
},
"source": {
"ip": "10.20.40.21"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add recurring reconnaissance episodes; false gives background only |
| anomaly_interval_hours | 24 | Source-time hours between episode due times; 2 to 8,760 |
| host_name | ns01.corp.example | Server name in host.name (configured context, not part of the native line) |
| zones | corp.example, contoso.example | Zones served; the first one gets most traffic. Use registrable names, since dns.question.registered_domain carries the zone |
| resolver_ips | 10.20.30.11, 10.20.30.12, 10.20.30.13, 10.20.30.14 | Recursive resolvers querying the server |
| client_prefix | 10.20.40. | Prefix of the directly connected clients |
| client_first | 21 | Last octet of the first direct client |
| client_count | 16 | Number of direct clients, at least 4; resolver and client addresses must not overlap |
Related Generators
Cisco ASA Firewall
Cisco ASA adaptive security appliance syslog — TCP/UDP/ICMP connection lifecycle, ACL permit/deny decisions, NAT translations, VPN tunnel events, and failover status messages.
Check Point Security Gateway
Check Point Security Gateway SmartLog — 8 software blades including Firewall, IPS, Application Control, URL Filtering, Anti-Bot, Anti-Virus, Threat Emulation, and Identity Awareness.
Network Traffic (Continent-Level Geo)
Network traffic events enriched with continent-level geographic information. Models cross-continent and same-continent flows for both inbound and outbound directions, with realistic allow/deny outcomes based on geographic policy.