INSPIRA - Configuring Microsoft DNS Debug To QRadar SIEM - v1.0
INSPIRA - Configuring Microsoft DNS Debug To QRadar SIEM - v1.0
The IBM QRadar DSM for Microsoft DNS Debug collects events from a Microsoft Windows system.
Note:
The following table describes the specifications for the Microsoft DNS Debug DSM:
To integrate Microsoft DNS Debug with QRadar, complete the following steps:
1. If automatic updates are not enabled, download and install the most recent version of the
following files from the IBM Support Website in the order that they are listed on your QRadar
Console:
• .sfs file for WinCollect
• DSMCommon RPM
• Microsoft DNS Debug RPM
2. Configure WinCollect to forward Microsoft DNS Debug events to QRadar. For more
information, go to Log Sources for WinCollect agents in the IBM QRadar WinCollect User
Guide. (https://www.ibm.com/
docs/en/SS42VS_SHR/com.ibm.wincollect.doc/c_ug_wincollect_log_sources.html).
3. If QRadar does not automatically detect the log source, add a Microsoft DNS Debug log
source on the QRadar Console.
Enabling DNS debugging on Windows Server
Enable DNS debugging on Windows Server to collect information that the DNS server sends and
receives.
Important: DNS debug logging can affect system performance and disk space because it provides
detailed data about information that the DNS server sends and receives. Enable DNS debug logging
only when you require this information.
Procedure
1. Open the DNS Manager with the following command:
dnsmgmt.msc
2. Right-click the DNS server and click Properties.
Important: The File path and name, need to align with the Root Directory and File Pattern you
provided when the Microsoft DNS debug log source was created in QRadar.
Important: Due to formatting issues, paste the message format into a text editor and then
remove any carriage return or line feed characters.
Microsoft DNS Debug sample message when you use the Syslog protocol
The following sample event shows a DNS type A query.