The CloudDnsEvents table in the advanced hunting schema contains information about DNS activity events from cloud infrastructure environments. Use this reference to construct queries that return information from this table.
Schema
Name
Description
Type
ActionType
Type of activity that triggered the event
String
AdditionalFields
Additional information about the entity or event
Object
AwsResourceName
The AWS resource name associated with the DNS event
String
AzureResourceId
The Azure Resource ID associated with the DNS event
String
ContainerId
The container identifier in Kubernetes or another runtime environment
String
ContainerName
Name of the container in Kubernetes or another runtime environment
String
DnsNetworkDuration
The amount of time, in milliseconds, for the completion of DNS request
Int64
DnsQuery
The domain that the request tries to resolve
String
DnsQueryTypeName
The DNS Resource Record Type names
String
DnsResponseCodeName
For DNS events, this field provides the DNS response code
String
EventSubType
Either ‘request’ or ‘response’
String
EventType
Indicates the operation reported by the record
String
GcpFullResourceName
The full GCP resource name associated with the DNS event
String
ImageName
The container image name or id
String
KubernetesNamespace
The Kubernetes namespace name
String
KubernetesPodName
The Kubernetes pod name
String
KubernetesResource
Unique identifier for the Kubernetes resource that includes the namespace, resource type and name
String
ProcessId
The process ID that initiated the DNS query/response
Int64
ProcessName
The command that performed the DNS query/response
String
ReportId
Unique identifier for the event
String
SourceSystem
String
TenantId
String
TimeGenerated
DateTime
Timestamp
Date and time when the record was generated
DateTime
TransactionIdHex
The DNS query unique ID as assigned by the DNS client, in hexadecimal format