↳ GitHub sourceConnector

DNS

Description

The DNS log connector allows you to easily connect your DNS analytic and audit logs with Microsoft Sentinel, and other related data, to improve investigation. **When you enable DNS log collection you can:** - Identify clients that try to resolve malicious domain names. - Identify stale resource records. - Identify frequently queried domain names and talkative DNS clients. - View request load on DNS servers. - View dynamic DNS registration failures. For more information, see the [Microsoft Sentinel documentation](https://go.microsoft.com/fwlink/p/?linkid=2220127&wt.mc_id=sentinel_dataconnectordocs_content_cnl_csasci).
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

read and write permissions.
Workspace
Workspace
[read and write permissions](https://docs.microsoft.com/azure/role-based-access-control/built-in-roles#log-analytics-contributor).
Solutions
ResourceGroup

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

1. Download and install the agent
> DNS logs are collected only from **Windows** agents.
Choose where to install the agent:
Install agent on Azure Windows Virtual Machine
Download the agent on the relevant machine and follow the instructions.
Install agent on non-Azure Windows Machine
Select the machine to install the agent and then click **Connect**.
2. Install DNS solution

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
DNS
Additional source files 2Solutions/Windows Server DNS/Data Connectors/template_DNS.JSONsource ↗Solutions/Windows Server DNS/Data/Solution_DNS.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.