Microsoft DNS Server Audit and Analytical Logs
Windows Server 2022 DNS Server Audit policy operations (577/580) and ETW Analytical query records (256/257/259) for one authoritative zone with recursion disabled, as ECS JSON in the shape the Elastic microsoft_dnsserver ingest pipeline produces. Not a Windows XML, EVTX or ETL export. Recurring episodes show an administrator creating an Ignore policy on a name they own, the policy dropping client queries, and the same administrator deleting it again within an hour.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/windows-dns-server-audit/generator.yml \
--id windows-dns-server-audit \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| 256 | QUERY_RECEIVED: incoming A query with source IP and port, XID, RD and DNS packet bytes | 50.00% share (50.00% without episodes) | network |
| 257 | RESPONSE_SUCCESS: authoritative A answer with the same client, port, XID and GUID | 49.17% share (46.9-49.1% without episodes) | network |
| 259 | IGNORED_QUERY: A query dropped by an Ignore policy, with no 257 following | 0.82% share (0.6-3.1% without episodes) | network |
| 577 | POLICY_OP: an administrator creates a server-level Ignore query policy | 0.004% share (0.003% without episodes) | none |
| 580 | POLICY_OP: an administrator deletes a policy | 0.004% share (0.003% without episodes) | none |
Realism Features
- About 57,000 records a day, varying about ±3% from day to day, on an hour-of-day curve in the generator time zone (UTC by default): 1.20 records/s at 08-17, 0.54 at 06-08 and 17-20, 0.24 at night. Sixty workstations send about 28,000 queries a day (retransmissions included), each with its own activity level; a lookup covers one name or up to six names resolved in parallel.
- An unmatched name gets a 257 answer with QR/AA/RD flags, RA clear, one A record and TTL 300. A name matching an active policy is dropped (259), and the client retransmits after 1, 1, 2 and 4 seconds as the Windows DNS client does; each retransmission is dropped while the policy is active and answered once it is gone. About 0.2-1.3% of client lookups are dropped, each bringing up to five 259 records.
- Five administrators create about two policies a day, mostly in office hours. Three own a name they block about once every two days (a.petrov is retiring legacy-crm, dns.ops blocks wpad, m.sokolova vendor telemetry); i.volkov and adm.kuznetsov act every few days on any target. A fifth of the policies are mistakes undone by their creator within a minute or so, about 40% are rolled back by a colleague after roughly half an hour, and the rest last about two hours or several hours; about one operation in eight deletes an active policy picked at random.
- Records follow the pinned Elastic parsed fixtures: native data under microsoft_dnsserver.*, pipeline ECS fields (network.*, dns.question.* with registered_domain, event.outcome, event.reason, related.*) and the rendered message. data_stream and host.name are always present; agent, cloud, geo/AS enrichment, event.created, event.ingested, event.agent_id_status and event.original are omitted.
- Reason=Policy, the policy name and the zone on a policy drop are inferred (published 259 examples carry Reason=System and PolicyName=NULL); 580 fields follow the documented message placeholders, ElapsedTime units are unproven, and retransmissions reusing XID and port is an assumption. An answer or drop follows its query after a median of 1.1 s and up to about 80 s at night, not within milliseconds as on a real server.
- Only A queries for existing records are modeled: no NXDOMAIN, other record types, TCP, recursion or zone and record changes. Query volume (about 0.3 queries per second on average), policy activity and lifetimes are synthetic. Outside episodes a creator never deletes its own policy within an hour after three or more drops, so now and then a policy stays active hours or days longer; with episodes, counts of the chain parts are about one per episode higher.
Sample Output
{
"@timestamp": "2026-09-04T08:34:28.653Z",
"data_stream": {
"dataset": "microsoft_dnsserver.analytical",
"namespace": "default",
"type": "logs"
},
"dns": {
"id": "31426",
"question": {
"name": "legacy-crm.corp.example.com",
"registered_domain": "example.com",
"subdomain": "legacy-crm.corp",
"top_level_domain": "com",
"type": "A"
}
},
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "LOOK_UP",
"category": [
"network"
],
"code": "259",
"dataset": "microsoft_dnsserver.analytical",
"kind": "event",
"provider": "Microsoft-Windows-DNSServer",
"reason": "Policy",
"severity": 2,
"type": [
"protocol"
]
},
"host": {
"name": "dns-01.corp.example.com"
},
"input": {
"type": "etw"
},
"log": {
"file": {
"path": "Microsoft-Windows-DNSServer-Analytical.etl"
},
"level": "error"
},
"message": "IGNORED_QUERY: TCP=0; InterfaceIP=; Source=10.20.5.100; Reason=Policy; QNAME=legacy-crm.corp.example.com.; QTYPE=1; XID=31426; Zone=corp.example.com; PolicyName=QueryFilter-legacy-crm-e3e7; AdditionalInfo = VirtualizationInstance: .",
"microsoft_dnsserver": {
"analytical": {
"additional_info": ".",
"description": "Ignored query",
"policy_name": "QueryFilter-legacy-crm-e3e7",
"question_name": "legacy-crm.corp.example.com.",
"question_type": "A",
"reason": "Policy",
"source": {
"ip": "10.20.5.100"
},
"xid": "31426",
"zone": "corp.example.com"
}
},
"network": {
"direction": "ingress",
"protocol": "dns",
"transport": "udp"
},
"process": {
"pid": 5868,
"thread": {
"id": 9992
}
},
"related": {
"ip": [
"10.20.5.100"
]
},
"source": {
"ip": "10.20.5.100"
},
"tags": [
"preserve_duplicate_custom_fields"
],
"user": {
"id": "NT AUTHORITY\\SYSTEM"
},
"winlog": {
"channel": "Microsoft-Windows-DNS-Server/Analytical",
"flags": [
"64_BIT_HEADER",
"EXTENDED_INFO",
"PROCESSOR_INDEX"
],
"flags_raw": "0x241",
"keywords": [
"IGNORED_QUERY"
],
"keywords_raw": "0x8000000000000008",
"level": "Error",
"level_raw": 2,
"opcode_raw": 0,
"provider_guid": "{EB79061A-A566-4698-9119-3ED2807060E7}",
"provider_message": "Microsoft-Windows-DNS-Server",
"session": "Microsoft-Windows-DNSServer-Analytical.etl",
"task": "LOOK_UP",
"task_raw": 1,
"version": 0
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| server_name | dns-01.corp.example.com | DNS server host name (host.name, winlog.computer_name, name_server) |
| server_ip | 10.20.0.53 | Server interface address (interface_ip on 256/257) |
| zone | corp.example.com | Authoritative zone reported on 257/259 |
| domain | CORP | Domain of the administrator accounts |
| domain_sid | S-1-5-21-1004336348-1177238915-682003330 | Domain SID; each account adds its RID |
| policy_name | QueryFilter | Policy name stem; names are <stem>-<target label>-<4 hex> |
| anomaly_mode | true | Enables the recurring episodes |
| anomaly_interval_hours | 72 | Episode interval in hours, 2 to 8760 |
Related Generators
Cisco ASA Firewall
Cisco ASA adaptive security appliance syslog — TCP/UDP/ICMP connection lifecycle, ACL permit/deny decisions, NAT translations, VPN tunnel events, and failover status messages.
Check Point Security Gateway
Check Point Security Gateway SmartLog — 8 software blades including Firewall, IPS, Application Control, URL Filtering, Anti-Bot, Anti-Virus, Threat Emulation, and Identity Awareness.
Network Traffic (Continent-Level Geo)
Network traffic events enriched with continent-level geographic information. Models cross-continent and same-continent flows for both inbound and outbound directions, with realistic allow/deny outcomes based on geographic policy.