Hub
Network

Unbound DNS Query and Reply Logs

Query and reply log of one Unbound 1.26.1 recursive resolver serving an office network: native query: and reply: lines from Unbound's own logfile in event.original, with ECS fields derived from each line. For DNS analytics and for testing detections of DNS tunnelling through TXT lookups. Recurring episodes show one client looking up a telemetry zone and then sending eight TXT lookups of new hex labels under it.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/network-unbound/generator.yml \
  --id network-unbound \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
AQuery and reply for corporate names and host-NNN71.0% of queries measurednetwork
AAAAQuery and reply for an AAAA record8.6% of queries measurednetwork
MX / corporate TXTQuery and reply for MX or corporate TXT (DMARC, DKIM, ACME)7.1% of queries measurednetwork
Telemetry zone AQuery and reply for the A record of a telemetry zone apex1.4% of queries measurednetwork
Telemetry hex TXTQuery and reply for TXT of a 32-hex label under a telemetry zone12.0% of queries measurednetwork

Realism Features

  • About 36,000 lines a day (queries and replies together) on the UTC clock: about 520 an hour at night (21:00-07:00), about 1,430 in the evening (17:00-21:00) and about 2,530 in office hours (07:00-17:00); each band varies by up to 3% a day.
  • Every query has exactly one reply on the same worker thread, following it by the resolution time plus 40-900 microseconds (8 ms median, 43 ms at the 90th percentile), usually on the next line. Unbound logs no query ID, so a reply is linked to its query by client, question and worker thread. 92.2% of replies are NOERROR, 7.8% NXDOMAIN, and 34.7% come from cache.
  • Each of the 70 default clients starts lookup sessions in proportion to its own fixed, log-normally skewed activity weight (0.4-3 times the typical client), so a few clients are much busier and every client is active every day. 30% of ordinary lookups are followed within seconds by a second lookup; lookups a real client sends within milliseconds are seconds apart here, 5 s in median within a burst and more at night.
  • Three telemetry zones stand for vendor services answering TXT lookups of hashed 32-hex labels. A run is 1-10 bursts (40% single) of a few lookups, separated by pauses with a median of 40 minutes; 3% of bursts are scans of a batch of hashes (median 8, up to 40), never the first burst after an A lookup. 15% of labels repeat a recent one, and a zone answers each label with TXT data (60%) or NXDOMAIN and keeps that answer.
  • A TTL cache of at most 256 entries (60 s for A/AAAA and zone apex, 180 s for corporate MX/TXT, 10 s for telemetry TXT data, 45-60 s for NXDOMAIN) drives the native from_cache flag: a cached reply carries 0.000000 and 1, an uncached one a log-normal resolution time (median 12 ms for corporate names, 45 ms for the telemetry zones). Response sizes are computed from the DNS message layout for the synthetic zone data; they are plausible values, not captured packet sizes.
  • Background carries every chain part in both modes: zone apex lookups, hex-label TXT runs with NXDOMAIN and data answers, lookups seconds apart, scans of 8 or more distinct labels, runs that start with the zone A lookup, and A lookups followed by several TXT lookups within 10 minutes; the client and zone of an episode also appear together in background TXT lookups, and usually in background A lookups. Ordinary traffic never holds eight hex TXT lookups by one client under one zone within 10 minutes of its A lookup of that zone; with anomaly_mode true, counts of zone A lookups followed by many hex TXT lookups within 10 minutes are about one per episode higher. The logs carry no answer data, so a match shows the pattern, not that data left the network.
  • The line grammar follows the Unbound 1.26.1 source formatter for the stated profile; no first-party runtime capture was found, so byte-level fidelity is unverified. @timestamp keeps microseconds while event.original has the logfile's millisecond precision; replies carry no destination address or transport; host name and dns.question.registered_domain (the last two labels) are collector enrichment. Zone data, TTLs, resolution times and client activity rates are synthetic, the telemetry zones use reserved example.* domains, and there is no forwarding, DNSSEC failure, SERVFAIL or rate limiting.

Sample Output

{
  "@timestamp": "2026-09-01T12:16:57.811304+00:00",
  "dns": {
    "question": {
      "class": "IN",
      "name": "16ad8c7e4fe9e9a6d4cb8a64afc0d5e9.telemetry.example.org.",
      "registered_domain": "example.org",
      "type": "TXT"
    },
    "response_code": "NXDOMAIN",
    "type": "answer"
  },
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "dns-reply",
    "category": [
      "network"
    ],
    "kind": "event",
    "original": "2026-09-01T12:16:57.811+00:00 unbound[2137:0] reply: 10.20.30.33 16ad8c7e4fe9e9a6d4cb8a64afc0d5e9.telemetry.example.org. TXT IN NXDOMAIN 0.034614 0 146",
    "type": [
      "end"
    ]
  },
  "host": {
    "name": "dns01.corp.example"
  },
  "process": {
    "name": "unbound",
    "pid": 2137
  },
  "related": {
    "ip": [
      "10.20.30.33"
    ]
  },
  "source": {
    "ip": "10.20.30.33"
  },
  "unbound": {
    "reply": {
      "from_cache": 0,
      "response_size": 146,
      "time_to_resolve": 0.034614
    },
    "worker_id": 0
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueEmit recurring tunnelling episodes; false gives background only
anomaly_interval_hours24Event-time hours between episodes; 2 to 8,760
host_namedns01.corp.exampleResolver host name in ECS enrichment
process_id2137Unbound process ID in the log lines
worker_count4Resolver threads (num-threads); at least 1
client_prefix10.20.30.Client address prefix
client_first11Last octet of the first client
client_count70Number of clients
tunnel_domainssync-updates.example.net, telemetry.example.org, cdn-check.example.comTelemetry zones used by background TXT runs and by episodes; at least two, on distinct registered domains

Related Generators