<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog - Collecting Internal DNS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226383#M65172</link>
    <description>&lt;P&gt;DNS Names for the IPs in the logs.&lt;BR /&gt;&lt;BR /&gt;I would love to know how to export that info.&lt;/P&gt;</description>
    <pubDate>Wed, 08 Aug 2018 00:15:59 GMT</pubDate>
    <dc:creator>JeffFredericks</dc:creator>
    <dc:date>2018-08-08T00:15:59Z</dc:date>
    <item>
      <title>Syslog - Collecting Internal DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/224644#M64480</link>
      <description>&lt;P&gt;Hey Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed my Syslog box isn't receiving internal DNS information from the Palo.&amp;nbsp; I originally thought the URL log type would capture internal information (yes i'm&amp;nbsp;aware what URL stands for, but I could hope).&amp;nbsp; However that doesn't seem to be the case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a particular field, log type, or severity level I can enable to collect internal dns&amp;nbsp;names and services?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jeff&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 17:56:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/224644#M64480</guid>
      <dc:creator>JeffFredericks</dc:creator>
      <dc:date>2018-08-02T17:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - Collecting Internal DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/224657#M64481</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm not sure if hte PAN does this for you or if there is a way to accomplish this. However for us our SIEM does this on its end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 18:55:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/224657#M64481</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-08-02T18:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - Collecting Internal DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/224717#M64494</link>
      <description>&lt;P&gt;What are you actualy trying to achive/log?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 11:14:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/224717#M64494</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-08-03T11:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - Collecting Internal DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226381#M65170</link>
      <description>&lt;P&gt;Trying to collect internal dns records in Palo Alto's Splunk app.&amp;nbsp; That way we can better correlate events and threats when they happen.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 23:51:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226381#M65170</guid>
      <dc:creator>JeffFredericks</dc:creator>
      <dc:date>2018-08-07T23:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - Collecting Internal DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226382#M65171</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/94682"&gt;@JeffFredericks&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Do you want to have DNS logs in your Splunk server or do you want the DNS names for the IPs in the logs? For the names you can export the DNS Names and create a lookup table on your splunk server.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 00:12:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226382#M65171</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-08T00:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - Collecting Internal DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226383#M65172</link>
      <description>&lt;P&gt;DNS Names for the IPs in the logs.&lt;BR /&gt;&lt;BR /&gt;I would love to know how to export that info.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 00:15:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226383#M65172</guid>
      <dc:creator>JeffFredericks</dc:creator>
      <dc:date>2018-08-08T00:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - Collecting Internal DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226395#M65175</link>
      <description>&lt;P&gt;Do we assume your DNS server is Windows Server??&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 07:54:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226395#M65175</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-08-08T07:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - Collecting Internal DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226396#M65176</link>
      <description>&lt;P&gt;And are all your IP's static/reserverd?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 07:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226396#M65176</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-08-08T07:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - Collecting Internal DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226508#M65209</link>
      <description>&lt;P&gt;Windows Server + Static/reserved&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 18:57:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226508#M65209</guid>
      <dc:creator>JeffFredericks</dc:creator>
      <dc:date>2018-08-08T18:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - Collecting Internal DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226585#M65220</link>
      <description>&lt;P&gt;You can export the zone via MMC, or you could powershel the export and run it periodicaly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 08:04:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226585#M65220</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-08-09T08:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - Collecting Internal DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226631#M65234</link>
      <description>&lt;P&gt;Interesting.&amp;nbsp; From what you described It sounds a little bit more like a hack, then an actual filter or setting with the Palo Alto as well.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Selecting, say, the url field for syslog won't capture internal DNS requests as they're hitting the Palo?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 18:05:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226631#M65234</guid>
      <dc:creator>JeffFredericks</dc:creator>
      <dc:date>2018-08-09T18:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - Collecting Internal DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226664#M65249</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/94682"&gt;@JeffFredericks&lt;/a&gt;&lt;/P&gt;&lt;P&gt;The way described by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;&amp;nbsp;isn't a hack. This is how it should be as the firewall also does not know the DNS names of the sources (except if you create address objects for ALL your internal systems). This information you should get where it is managed -&amp;gt; from your DNS server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/94682"&gt;@JeffFredericks&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Selecting, say, the url field for syslog won't capture internal DNS requests as they're hitting the Palo?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;No, paloalto does not log the content of DNS requests. If you need this data, then the best place to get that is agsin your DNS server which you need to configure to send the DNS logs to your splunk server.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 22:31:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226664#M65249</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-09T22:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog - Collecting Internal DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226687#M65257</link>
      <description>&lt;P&gt;Even if the PA did see the DNS requests ( if you had the DNS servers on their own Zone or Subnet) routed through the firewall.... The PA is not goign to do anything special with the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 09:30:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-collecting-internal-dns/m-p/226687#M65257</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-08-10T09:30:15Z</dc:date>
    </item>
  </channel>
</rss>

