# Microsoft DNS Server integration - remove dot at domainn name's end

**URL:** <https://discuss.elastic.co/t/microsoft-dns-server-integration-remove-dot-at-domainn-names-end/380457>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [July 25, 2025, 6:55am UTC](https://discuss.elastic.co/t/microsoft-dns-server-integration-remove-dot-at-domainn-names-end/380457 "2025-07-25T06:55:10Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zer0-cyber-web](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zer0-cyber-web/32/144318_2.png) [@Zer0-cyber-web](https://discuss.elastic.co/u/Zer0-cyber-web)\
**Post date:** [July 25, 2025, 6:55am UTC](https://discuss.elastic.co/t/microsoft-dns-server-integration-remove-dot-at-domainn-names-end/380457/1 "2025-07-25T06:55:10Z")

</div>

Hi!  
Could someone point me where to look: in Microsoft DNS Server index, there is a field with requested domain name - **dns.question.name**. It contains domain name that was requested by client. The only problem is that after parsing from oroginal Windows server log - it contains additional dot at the end:

```auto
lh3.google.com.

```

so it could look like:

```auto
lh3.google.com

```

Is there any way to get rid of this dot, so I could use this field in Custom match rule?  
Thanks a lot in advance.

PS: Just in case _data\_stream.dataset: microsoft\_dnsserver.analytical_

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 26, 2025, 3:15pm UTC](https://discuss.elastic.co/t/microsoft-dns-server-integration-remove-dot-at-domainn-names-end/380457/2 "2025-07-26T15:15:24Z")

</div>

Hi @Zer0-cyber-web Welcome to the community.

What version of the Elastic Stack

What version of the integration

Can you turn on the preserve original event in the integration and see if that is part of the origin event?

Can you share one of the final JSON documents that show this behavior...

Please share

May or may not be a bug. Even if it is we can probably do a work around

It looks like this is part of the expected data

> <https://github.com/elastic/integrations/blob/ecb85b24a0278451a31c803ffd758894f85963b5/packages/microsoft_dnsserver/data_stream/analytical/_dev/test/pipeline/test-events.json#L20>

I asked internally as well.

---

<div class="post-metadata">

**Author:** ![Zer0-cyber-web](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zer0-cyber-web/32/144318_2.png) [@Zer0-cyber-web](https://discuss.elastic.co/u/Zer0-cyber-web)\
**Post date:** [July 28, 2025, 7:08am UTC](https://discuss.elastic.co/t/microsoft-dns-server-integration-remove-dot-at-domainn-names-end/380457/3 "2025-07-28T07:08:31Z")

</div>

Hi Stephen!  
Thanks a lot for reply.  
Elastic Stack I am using as part of Security Onion (2.4.160), Elastic version is 8.17.3.  
Integration - Microsoft DNS Server v1.2.0 (that is the only available in my Integrations section, despite github has already v1.4.0)  
I turned on "Preserve original event" in the integration, but don't see any event.original field at the moment...

Existing event json part:

```json
"process": {
      "pid": 2644,
      "thread": {
        "id": 5820
      }
    },
    "winlog": {
      "keywords": [
        "RESPONSE_SUCCESS"
      ],
      "provider_guid": "{EB79061A-A566-4698-9119-3ED2807060E7}",
      "session": "Elastic-DNSServer-Analytical",
      "flags": "576",
      "channel": "16",
      "activity_id": "{00000000-0000-0000-0000-000000000000}",
      "opcode": "0",
      "version": 0
    },
    "log": {
      "level": "information"
    },
    "elastic_agent": {
      "id": "ead4219b-696a-4de9-9164-f702a6c832e4",
      "version": "8.17.3",
      "snapshot": false
    },
    "dns": {
      "response_code": "NoError",
      "question": {
        "name": "c.idealmedia.io.",
        "type": "A"
      },
      "id": "64509"
    },
    "destination": {
      "port": 56591,
      "ip": "192.168.8.246"
    },
    "microsoft_dnsserver": {
      "analytical": {
        "dnssec": "0",
        "packet_data": "0xFBFD8180000100020000000001630A696465616C6D6564696102696F0000010001C00C000100010000009400046812A442C00C0001000100000094000468128C0F",
        "destination": {},
        "description": "Response success",
        "additional_info": "VirtualizationInstance:.",
        "zone": "..Cache",
        "scope": "Default",
        "guid": "{036ED18C-DEF3-4505-9B82-9782568FCD03}",
      }

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 28, 2025, 3:03pm UTC](https://discuss.elastic.co/t/microsoft-dns-server-integration-remove-dot-at-domainn-names-end/380457/4 "2025-07-28T15:03:40Z")

</div>

Hi @Zer0-cyber-web

Per Engineering

> Trailing dots(`.`) are common in DNS data as this indicates it is a FQDN.  
> `microsoft_dnsserver` version `1.4.0` will populate `dns.question.name` field without the trailing dot. ([PR Reference](https://github.com/elastic/integrations/pull/14336))

I think you need to focus on why you only have Version 1.2 of the integration... Did you trying update the integration? In my Environment 1.4 is available.

---

<div class="post-metadata">

**Author:** ![Zer0-cyber-web](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zer0-cyber-web/32/144318_2.png) [@Zer0-cyber-web](https://discuss.elastic.co/u/Zer0-cyber-web)\
**Post date:** [July 29, 2025, 6:47am UTC](https://discuss.elastic.co/t/microsoft-dns-server-integration-remove-dot-at-domainn-names-end/380457/5 "2025-07-29T06:47:07Z")

</div>

Hi Stephen.

Thank you.

Well, it is not about “why there is a dot”. For me it is about using this field in Indicator match rule, and this trailing dot does not allow to perform comparison. That is the only reason I started to look around.  
Regarding version - is there any way to install new version manually? I don’t know why my integration page suggests only v1.2.0. Any ideas?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 29, 2025, 4:38pm UTC](https://discuss.elastic.co/t/microsoft-dns-server-integration-remove-dot-at-domainn-names-end/380457/6 "2025-07-29T16:38:08Z")

</div>

> [@Zer0-cyber-web](#):
>
> Regarding version - is there any way to install new version manually? I don’t know why my integration page suggests only v1.2.0. Any ideas?

Show me the settings page,

No I am not sure why...

You can try installing it manually

> **[Install a package from the registry | Kibana API documentation (v9)](https://www.elastic.co/docs/api/doc/kibana/v9/operation/operation-post-fleet-epm-packages-pkgname-pkgversion)**
>
> \[Required authorization\] Route required privileges: integrations-all AND fleet-agent-policies-all.

In Kibana Dev Tools

`POST kbn:/api/fleet/epm/packages/microsoft_dnsserver/1.4.0`

---

<div class="post-metadata">

**Author:** ![Zer0-cyber-web](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zer0-cyber-web/32/144318_2.png) [@Zer0-cyber-web](https://discuss.elastic.co/u/Zer0-cyber-web)\
**Post date:** [July 31, 2025, 2:08pm UTC](https://discuss.elastic.co/t/microsoft-dns-server-integration-remove-dot-at-domainn-names-end/380457/7 "2025-07-31T14:08:52Z")

</div>

Security Onion people says that is because they still use 8.17.3. And they think that v1.4.0 is available only from Elastic 8.19… Can this be a reason?  
DevTools said “not found”.

 ![зображення](https://us1.discourse-cdn.com/elastic/original/3X/8/5/852dbc2ddbda5d2e844f5d33252d66db9697e98e.png)

Settings page:

 ![зображення](https://us1.discourse-cdn.com/elastic/original/3X/5/d/5d120679576dca8a53020638eba1a6bb3904ee06.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 31, 2025, 9:18pm UTC](https://discuss.elastic.co/t/microsoft-dns-server-integration-remove-dot-at-domainn-names-end/380457/8 "2025-07-31T21:18:45Z")

</div>

This is a fresh Elastic Cloud 8.17.3 and Support Integration 1.4

Readme says :

The minimum **kibana.version** required is **8.13.0**.

I suspect your issue has something to do with the Integration Repository EPR I suspect not updating..

 ![Screen Shot 2025-07-31 at 2.15.44 PM](https://us1.discourse-cdn.com/elastic/original/3X/d/c/dc902b067b80e1d4ccd1f223efbbb07621d56da1.png)

 ![Screen Shot 2025-07-31 at 2.16.04 PM](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c95b93c2ed0e67871fc97a5077f136d7856f17a2.jpeg)

If all else fails...

Clone the Elastic Integrations repostory

Built this Package

Upload it

> **[integrations/packages/microsoft\_dnsserver at main · elastic/integrations](https://github.com/elastic/integrations/tree/main/packages/microsoft_dnsserver#requirements)**
>
> Contribute to elastic/integrations development by creating an account on GitHub.

---

<div class="post-metadata">

**Author:** ![Zer0-cyber-web](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zer0-cyber-web/32/144318_2.png) [@Zer0-cyber-web](https://discuss.elastic.co/u/Zer0-cyber-web)\
**Post date:** [August 4, 2025, 6:15am UTC](https://discuss.elastic.co/t/microsoft-dns-server-integration-remove-dot-at-domainn-names-end/380457/9 "2025-08-04T06:15:55Z")

</div>

Thank you. In fact - Security Onion seems to use they own repository, which contains only checked integrations. But they promised to update it in next release.
