# SysMon DNS Logs - dns.answers - Types

**URL:** <https://discuss.elastic.co/t/sysmon-dns-logs-dns-answers-types/213471>\
**Category:** Beats\
**Created:** [December 31, 2019, 10:49pm UTC](https://discuss.elastic.co/t/sysmon-dns-logs-dns-answers-types/213471 "2019-12-31T22:49:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nicholas\_Penning](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicholas_penning/32/55736_2.png) [@Nicholas\_Penning](https://discuss.elastic.co/u/Nicholas_Penning)\
**Post date:** [December 31, 2019, 10:49pm UTC](https://discuss.elastic.co/t/sysmon-dns-logs-dns-answers-types/213471/1 "2019-12-31T22:49:21Z")

</div>

Hello,

We are currently leveraging SysMon DNS logs and would like to have the capability to search/aggregrate on the types from the dns.answers that WinLogBeat ships to Elastic.

Currently, the dns.answers field contains:

{  
"data": "[elasticsearch.trainingrocket.com](http://elasticsearch.trainingrocket.com)",  
"type": "CNAME"  
},  
{  
"data": "[d1bzcgvkzhwrpe.cloudfront.net](http://d1bzcgvkzhwrpe.cloudfront.net)",  
"type": "CNAME"  
},  
{  
"data": "13.227.45.18",  
"type": "A"  
},  
{  
"data": "13.227.45.48",  
"type": "A"  
},  
{  
"data": "13.227.45.74",  
"type": "A"  
},  
{  
"data": "13.227.45.36",  
"type": "A"  
}

It would be great if this was parsed similarly to the dns.resolved\_ip field to show something like:  
dns.resolved.type or dns.answers.type to contain:  
CNAME, A

It doesn't seem that this is the case as noted on github ([https://github.com/elastic/beats/pull/12960](https://github.com/elastic/beats/pull/12960)):  
`winlog.event_data.QueryResults` -\> `dns.answers.data` , `dns.answers.type`

Is this a bug or to be expected?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 20, 2020, 2:46pm UTC](https://discuss.elastic.co/t/sysmon-dns-logs-dns-answers-types/213471/2 "2020-01-20T14:46:03Z")

</div>

This is following the [Elastic Common Schema](https://www.elastic.co/guide/en/ecs/current/ecs-dns.html) which does not have a field specifically for the CNAME values like it does for IPs in `dns.resolved_ip`. So this is the expected output.

What problem is this causing you?

---

<div class="post-metadata">

**Author:** ![Nicholas\_Penning](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicholas_penning/32/55736_2.png) [@Nicholas\_Penning](https://discuss.elastic.co/u/Nicholas_Penning)\
**Post date:** [January 20, 2020, 6:17pm UTC](https://discuss.elastic.co/t/sysmon-dns-logs-dns-answers-types/213471/3 "2020-01-20T18:17:04Z")

</div>

Hey thanks for the reply!

I was looking for the capability to search and aggregate on the record types and domain answers.

This is how the data looks in Kibana today:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7ebd894b6a617be4c76eb83609b9e3c9a304af1b.png)

I think having at least "dns.answers.data" : "[dualstack.r2.shared.global.fastly.net](http://dualstack.r2.shared.global.fastly.net), 151.101.150.217" and "dns.answers.type" : "CNAME, A" would at least allow us to do a pretty efficient search.

Perhaps this might be a mapping issue to give us searchable types/data?

"dns": {  
"resolved\_ip": [  
"151.101.150.217"  
],  
"question": {  
"registered\_domain": "[elastic.co](http://elastic.co)",  
"name": "[static-www.elastic.co](http://static-www.elastic.co)"  
},  
"answers": [  
{  
"data": "[dualstack.r2.shared.global.fastly.net](http://dualstack.r2.shared.global.fastly.net)",  
"type": "CNAME"  
},  
{  
"data": "151.101.150.217",  
"type": "A"  
}  
]  
},

Does that make sense?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2020, 8:24pm UTC](https://discuss.elastic.co/t/sysmon-dns-logs-dns-answers-types/213471/4 "2020-02-17T20:24:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
