stephenb
(Stephen Brown)
July 26, 2025, 3:15pm
2
Hi @Zer0-cyber-web Welcome to the community.
What version of the Elastic Stack
What version of the integration
Can you turn on the preserve original event in the integration and see if that is part of the origin event?
Can you share one of the final JSON documents that show this behavior...
Please share
May or may not be a bug. Even if it is we can probably do a work around
It looks like this is part of the expected data
"provider_guid": "{EB79061A-A566-4698-9119-3ED2807060E7}",
"session": "Elastic-DNSServer-Analytical",
"channel": "16",
"flags": "576",
"event_data": {
"AA": "0",
"TCP": "0",
"AdditionalInfo": "VirtualizationInstance:.",
"Destination": "216.160.83.56",
"AD": "0",
"QNAME": "google.es.",
"Zone": "..Cache",
"Port": "59560",
"GUID": "{BF629903-4288-435F-9182-470BEDF5C0A4}",
"ElapsedTime": "9",
"Flags": "33152",
"BufferSize": "55",
"XID": "7",
"DNSSEC": "0",
"Scope": "Default",
"QTYPE": "28",
I asked internally as well.