Hub
Network

Microsoft DNS Server Audit and Analytical Logs

Windows Server 2022 DNS Server Audit policy operations (577/580) and ETW Analytical query records (256/257/259) for one authoritative zone with recursion disabled, as ECS JSON in the shape the Elastic microsoft_dnsserver ingest pipeline produces. Not a Windows XML, EVTX or ETL export. Recurring episodes show an administrator creating an Ignore policy on a name they own, the policy dropping client queries, and the same administrator deleting it again within an hour.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/windows-dns-server-audit/generator.yml \
  --id windows-dns-server-audit \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
256QUERY_RECEIVED: incoming A query with source IP and port, XID, RD and DNS packet bytes50.00% share (50.00% without episodes)network
257RESPONSE_SUCCESS: authoritative A answer with the same client, port, XID and GUID49.17% share (46.9-49.1% without episodes)network
259IGNORED_QUERY: A query dropped by an Ignore policy, with no 257 following0.82% share (0.6-3.1% without episodes)network
577POLICY_OP: an administrator creates a server-level Ignore query policy0.004% share (0.003% without episodes)none
580POLICY_OP: an administrator deletes a policy0.004% share (0.003% without episodes)none

Realism Features

  • About 57,000 records a day, varying about ±3% from day to day, on an hour-of-day curve in the generator time zone (UTC by default): 1.20 records/s at 08-17, 0.54 at 06-08 and 17-20, 0.24 at night. Sixty workstations send about 28,000 queries a day (retransmissions included), each with its own activity level; a lookup covers one name or up to six names resolved in parallel.
  • An unmatched name gets a 257 answer with QR/AA/RD flags, RA clear, one A record and TTL 300. A name matching an active policy is dropped (259), and the client retransmits after 1, 1, 2 and 4 seconds as the Windows DNS client does; each retransmission is dropped while the policy is active and answered once it is gone. About 0.2-1.3% of client lookups are dropped, each bringing up to five 259 records.
  • Five administrators create about two policies a day, mostly in office hours. Three own a name they block about once every two days (a.petrov is retiring legacy-crm, dns.ops blocks wpad, m.sokolova vendor telemetry); i.volkov and adm.kuznetsov act every few days on any target. A fifth of the policies are mistakes undone by their creator within a minute or so, about 40% are rolled back by a colleague after roughly half an hour, and the rest last about two hours or several hours; about one operation in eight deletes an active policy picked at random.
  • Records follow the pinned Elastic parsed fixtures: native data under microsoft_dnsserver.*, pipeline ECS fields (network.*, dns.question.* with registered_domain, event.outcome, event.reason, related.*) and the rendered message. data_stream and host.name are always present; agent, cloud, geo/AS enrichment, event.created, event.ingested, event.agent_id_status and event.original are omitted.
  • Reason=Policy, the policy name and the zone on a policy drop are inferred (published 259 examples carry Reason=System and PolicyName=NULL); 580 fields follow the documented message placeholders, ElapsedTime units are unproven, and retransmissions reusing XID and port is an assumption. An answer or drop follows its query after a median of 1.1 s and up to about 80 s at night, not within milliseconds as on a real server.
  • Only A queries for existing records are modeled: no NXDOMAIN, other record types, TCP, recursion or zone and record changes. Query volume (about 0.3 queries per second on average), policy activity and lifetimes are synthetic. Outside episodes a creator never deletes its own policy within an hour after three or more drops, so now and then a policy stays active hours or days longer; with episodes, counts of the chain parts are about one per episode higher.

Sample Output

{
  "@timestamp": "2026-09-04T08:34:28.653Z",
  "data_stream": {
    "dataset": "microsoft_dnsserver.analytical",
    "namespace": "default",
    "type": "logs"
  },
  "dns": {
    "id": "31426",
    "question": {
      "name": "legacy-crm.corp.example.com",
      "registered_domain": "example.com",
      "subdomain": "legacy-crm.corp",
      "top_level_domain": "com",
      "type": "A"
    }
  },
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "LOOK_UP",
    "category": [
      "network"
    ],
    "code": "259",
    "dataset": "microsoft_dnsserver.analytical",
    "kind": "event",
    "provider": "Microsoft-Windows-DNSServer",
    "reason": "Policy",
    "severity": 2,
    "type": [
      "protocol"
    ]
  },
  "host": {
    "name": "dns-01.corp.example.com"
  },
  "input": {
    "type": "etw"
  },
  "log": {
    "file": {
      "path": "Microsoft-Windows-DNSServer-Analytical.etl"
    },
    "level": "error"
  },
  "message": "IGNORED_QUERY: TCP=0; InterfaceIP=; Source=10.20.5.100; Reason=Policy; QNAME=legacy-crm.corp.example.com.; QTYPE=1; XID=31426; Zone=corp.example.com; PolicyName=QueryFilter-legacy-crm-e3e7; AdditionalInfo = VirtualizationInstance: .",
  "microsoft_dnsserver": {
    "analytical": {
      "additional_info": ".",
      "description": "Ignored query",
      "policy_name": "QueryFilter-legacy-crm-e3e7",
      "question_name": "legacy-crm.corp.example.com.",
      "question_type": "A",
      "reason": "Policy",
      "source": {
        "ip": "10.20.5.100"
      },
      "xid": "31426",
      "zone": "corp.example.com"
    }
  },
  "network": {
    "direction": "ingress",
    "protocol": "dns",
    "transport": "udp"
  },
  "process": {
    "pid": 5868,
    "thread": {
      "id": 9992
    }
  },
  "related": {
    "ip": [
      "10.20.5.100"
    ]
  },
  "source": {
    "ip": "10.20.5.100"
  },
  "tags": [
    "preserve_duplicate_custom_fields"
  ],
  "user": {
    "id": "NT AUTHORITY\\SYSTEM"
  },
  "winlog": {
    "channel": "Microsoft-Windows-DNS-Server/Analytical",
    "flags": [
      "64_BIT_HEADER",
      "EXTENDED_INFO",
      "PROCESSOR_INDEX"
    ],
    "flags_raw": "0x241",
    "keywords": [
      "IGNORED_QUERY"
    ],
    "keywords_raw": "0x8000000000000008",
    "level": "Error",
    "level_raw": 2,
    "opcode_raw": 0,
    "provider_guid": "{EB79061A-A566-4698-9119-3ED2807060E7}",
    "provider_message": "Microsoft-Windows-DNS-Server",
    "session": "Microsoft-Windows-DNSServer-Analytical.etl",
    "task": "LOOK_UP",
    "task_raw": 1,
    "version": 0
  }
}

Parameters

ParameterDefaultDescription
server_namedns-01.corp.example.comDNS server host name (host.name, winlog.computer_name, name_server)
server_ip10.20.0.53Server interface address (interface_ip on 256/257)
zonecorp.example.comAuthoritative zone reported on 257/259
domainCORPDomain of the administrator accounts
domain_sidS-1-5-21-1004336348-1177238915-682003330Domain SID; each account adds its RID
policy_nameQueryFilterPolicy name stem; names are <stem>-<target label>-<4 hex>
anomaly_modetrueEnables the recurring episodes
anomaly_interval_hours72Episode interval in hours, 2 to 8760

Related Generators