dnschef icon indicating copy to clipboard operation
dnschef copied to clipboard

Request the output result send to SIEM

Open jjjan opened this issue 7 years ago • 1 comments

add output of sinkholed and malicious domain detection to SIEM such as splunk.

jjjan avatar Jan 08 '18 07:01 jjjan

good request we need the data send to SIEM in real time with this standard. for example time,src ip, src port,dst ip,dst port, request domain, if malicious domain detect(write it here), ref(which service detect that for example google dns, if blocked(by user intent), and etc that's you think useful. thanks

dpicollege avatar Jan 10 '18 13:01 dpicollege