# New sysmon event\_id 22, DNS Query

**URL:** <https://discuss.elastic.co/t/new-sysmon-event-id-22-dns-query/194635>\
**Category:** Beats\
**Created:** [August 9, 2019, 2:26pm UTC](https://discuss.elastic.co/t/new-sysmon-event-id-22-dns-query/194635 "2019-08-09T14:26:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ian\_Boje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ian_boje/32/52033_2.png) [@Ian\_Boje](https://discuss.elastic.co/u/Ian_Boje)\
**Post date:** [August 9, 2019, 2:26pm UTC](https://discuss.elastic.co/t/new-sysmon-event-id-22-dns-query/194635/1 "2019-08-09T14:26:42Z")

</div>

Hi Everybody

I'm not much of a programmer, but I'm tempted to try to learn to submit some changes to winlogbeat, but would be interested in finding out if I'm doing this right. Newer versions of sysmon added event\_id 22, which is a DNS query by a specific process.

I've modified the winlogbeat-sysmon.js file to rename fields based on [https://www.elastic.co/guide/en/beats/packetbeat/current/exported-fields-dns.html](https://www.elastic.co/guide/en/beats/packetbeat/current/exported-fields-dns.html). Here's what I've changed winlogbeat\sysmon\config\winlogbeat-sysmon.js, added:

```
    var event22 = new processor.Chain()
    .Add(parseUtcTime)
    .Convert({
        fields: [
            {from: "winlog.event_data.UtcTime", to: "@timestamp"},
            {from: "winlog.event_data.ProcessGuid", to: "process.entity_id"},
            {from: "winlog.event_data.ProcessId", to: "process.pid", type: "long"},
            {from: "winlog.event_data.Image", to: "process.executable"},
			{from: "winlog.event_data.QueryName", to: "dns.question.name"},
			{from: "winlog.event_data.QueryResults", to: "dns.answers"},
        ],
        mode: "rename",
        ignore_missing: true,
        fail_on_error: false,
    })
    .Add(setProcessNameUsingExe)
    .Add(removeEmptyEventData)
    .Build();
-snip-
	// Event ID 22 - Dns Query
	22: event22.Run,

```

Does this look good? I'm not sure if this complies with the ECS format. I'd also like to get this contributed to the github repo, but that might take too much time for me.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 12, 2019, 4:07am UTC](https://discuss.elastic.co/t/new-sysmon-event-id-22-dns-query/194635/2 "2019-08-12T04:07:28Z")

</div>

Hi Ian, support for event ID 22 was added in [https://github.com/elastic/beats/pull/12960](https://github.com/elastic/beats/pull/12960). This hasn't been released yet. It uses the fields proposed in [https://github.com/elastic/ecs/pull/438](https://github.com/elastic/ecs/pull/438).

---

<div class="post-metadata">

**Author:** ![Ian\_Boje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ian_boje/32/52033_2.png) [@Ian\_Boje](https://discuss.elastic.co/u/Ian_Boje)\
**Post date:** [August 12, 2019, 12:54pm UTC](https://discuss.elastic.co/t/new-sysmon-event-id-22-dns-query/194635/3 "2019-08-12T12:54:20Z")

</div>

That's great to see. It looks much better than what I did. Now I just have to decide if I should wait for the release, or compile from source.

Thanks for the help

Ian

---

<div class="post-metadata">

**Author:** ![rvrsh3ll](https://avatars.discourse-cdn.com/v4/letter/r/e9c0ed/32.png) [@rvrsh3ll](https://discuss.elastic.co/u/rvrsh3ll)\
**Post date:** [August 17, 2019, 4:24pm UTC](https://discuss.elastic.co/t/new-sysmon-event-id-22-dns-query/194635/4 "2019-08-17T16:24:52Z")

</div>

Hey, I tried this today. Compiled from 8/27/2019 github. I have sysmon 10 running and the dns requests are being logged as event id 22. Looking at elasticsearch, it looks like the events are being forwarded. 👍

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2019, 6:24pm UTC](https://discuss.elastic.co/t/new-sysmon-event-id-22-dns-query/194635/5 "2019-09-14T18:24:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
