I want to use elastic siem for my DNS server logs,
we are using a BIND DNS server, I don't want to install Packetbeat/Filebeat on the DNS server machine. we use syslog-ng to redirect DNS server logs to UDP port 514.
This is how my logs look like: (I get these result using nc -luv 514)
<13>Sep 6 08:17:39 ns BIND-DNS: 08:17:39.181 resolver: debug 1: createfetch: telemetry.dropbox.com A <13>Sep 6 08:17:39 ns BIND-DNS: 08:17:39.283 database: debug 1: decrement_reference: delete from rbt: 0x7f38645f44e0 g.live.com <13>Sep 6 08:17:39 ns BIND-DNS: 08:17:39.294 resolver: debug 1: createfetch: telemetry.v.dropbox.com A <13>Sep 6 08:17:33 ns BIND-DNS: 08:17:35.173 queries: info: client 192.168.30.114#51723 (www.google.com): query: www.google.com IN A + (192.168.100.35)
I'm really confused and I don't have any idea what should I use, packetbeat (dns module)? filebeat dns/udp/syslog? I have tried with packetbeat and filebeat but I can't get it to work
can someone please point me in the right direction?