We are ingesting some SysMon (Version 10.41) DNS logs via WinLogbeat 7.4.0 and have found that some status codes are not either getting translated with the sysmon.js or are not in the list. I will focus on the event log that is in the list. The status is 9560 which should be displaying as DNS_ERROR_INVALID_NAME_CHAR but instead the logs in Kibana are showing 9560.
You can test this by trying to ping www.google,com
You see that the status code is in fact 9560 in the Windows event log but for some reason the sysmon.js doesn't clean up like most of the other DNS queries. Any ideas?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.