DNS Analytical ? #14913
-
Has anyone experienced issues with Elastic Windows DNS server integration? Since 07/29, we have stopped receiving DNS Analytical logs. On that day, no changes were made to the DNS server or the SO stack. We checked on DNS server istelf logs are generating, on security onions logs I cant find any errors also. maybe somebody have any idea ? From elastic agent logs it seems like it runing: ETW session also runing: Name: Elastic-DNSServer-Analytical\Elastic-DNSServer-Analytical Provider: |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Are you able to upgrade to 2.4.170 which includes updates to integration packages |
Beta Was this translation helpful? Give feedback.
Not it seems working as it is. What we did is manually stoped ETW sessions which was reading from DNS-Analytical by running logman stop " " -ets . When restarted elastic egent it recreated session ELASTIC-DNS-Analytical and it stared working again.