Getting Data In

How to detect users using DNS different than organization DNS

abdallahalhabba
New Member

Dear All
Good Day
I need search detect users using DNS different than Organization DNS. Please share me your ideas & suggestion .

Tags (2)
0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @abdallahalhabbash, If richgalloway solved your problem, please remember to "Accept" his answer to award karma points. 🙂

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Assuming you're already collecting network metadata (either from Stream, your proxy server, firewall logs, etc.) then you just need to look for events going to port 53 with a destination IP address not in your network.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

[Puzzles] Solve, Learn, Repeat: Family Trees

This puzzle (first published here is based on finding grandparents and grandchildren (inspired by a question ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...