The 1 hit in Kibana
{
"ts": "2020-04-18T17:45:10.783496Z",
"uid": "C1hMM64CCTc971GJGd",
"id.orig_h": "192.168.1.10",
"id.orig_p": 58952,
"id.resp_h": "192.168.1.1",
"id.resp_p": 53,
"proto": "udp",
"trans_id": 37980,
"rtt": 0.030848026275634766,
"query": "logincdn.msauth.net",
"qclass": 1,
"qclass_name": "C_INTERNET",
"qtype": 1,
"qtype_name": "A",
"rcode": 0,
"rcode_name": "NOERROR",
"AA": false,
"TC": false,
"RD": true,
"RA": true,
"Z": 0,
"answers": ["lgincdn.trafficmanager.net", "lgincdnvzeuno.azureedge.net", "lgincdnvzeuno.ec.azureedge.net", "cs1227.wpc.alphacdn.net", "192.229.221.185"],
"TTLs": [155.0, 29.0, 1158.0, 3599.0, 1123.0],
"rejected": false
}
18 hits in Elastic, here is one hit, it's similar, but not a perfect match
answers: ["cs199.wpc.alphacdn.net", "68.232.34.228"]
destination_ips: "192.168.1.1"
source_ip: "192.168.1.10"
protocol: "udp"
event_type: "bro_dns"
destination_ip: "192.168.1.1"
parent_domain_length: 5
syslog-facility: "user"
host: "gateway"
query_class: 1
aa: false
transaction_id: 22868
syslog-priority: "notice"
query: "files3.lynda.com"
rcode: 0
query_type: 1
subdomain_frequency_score: 7.5615
ips: ["192.168.1.10", "192.168.1.1"]
syslog-host: "seconion-NU691"
ra: true
tags: ["syslogng", "bro", "dns", "top-1m", "internal_destination", "internal_source"]
ttls: [40, 3370]
rd: true
port: 50718
subdomain: "files3"
syslog-tags: ".source.s_bro_dns"
frequency_scores: ["8.2685", "7.5615"]
syslog-host_from: "seconion-nu691"
parent_domain: "lynda"
syslog-sourceip: "127.0.0.1"
query_class_name: "C_INTERNET"
highest_registered_domain: "lynda.com"
top_level_domain: "com"
destination_port: 53
rejected: false
source_ips: "192.168.1.10"
uid: "CkeLOB18R37pFLbtr3"
highest_registered_domain_frequency_score: 8.2685
source_port: 60965
syslog-file_name: "/nsm/bro/logs/current/dns.log"
@version: "1"
timestamp: "2020-04-03T09:05:38.475Z"
logstash_time: 0.02882218360900879
message: "{"ts":"2020-04-03T09:05:37.392974Z","uid":"CkeLOB18R37pFLbtr3","id.orig_h":"192.168.1.10","id.orig_p":60965,"id.resp_h":"192.168.1.1","id.resp_p":53,"proto":"udp","trans_id":22868,"rtt":0.0424351692199707,"query":"files3.lynda.com","qclass":1,"qclass_name":"C_INTERNET","qtype":1,"qtype_name":"A","rcode":0,"rcode_name":"NOERROR","AA":false,"TC":false,"RD":true,"RA":true,"Z":0,"answers":["cs199.wpc.alphacdn.net","68.232.34.228"],"TTLs":[40.0,3370.0],"rejected":false}"
tld: {subdomain: "files3.lynda.com"}
subdomain_length: 6
tc: "false"
rcode_name: "NOERROR"
query_length: 16
rtt: 0.0424351692199707
@timestamp: "2020-04-03T09:05:37.392Z"
query_type_name: "A"
z: 0