Fortinet black logo

FortiSIEM Reference Architecture Using ClickHouse

DNS

DNS

FortiSIEM can be configured to perform DNS resolution of parsed IP address fields as part of event processing and enrichment. This allows the analyst to see the domain name of the address when reviewing logs and performing investigations.

If enabled, DNS resolution is performed by the ingesting node as the event is processed. This could be a collector at a remote site in a distributed solution. When using this feature, design the supporting DNS services to provide resolution of addresses received by the system at the point of ingestion, and ensure the nodes are configured with the correct DNS server addresses to allow the request to be sent.

Failing to provide suitable DNS services will result in many failed DNS requests on the node, which can impact performance. If the deployment scenario prevents adequate DNS services being deployed and the node is experiencing DNS based performance issues, disable DNS for the entire node by modifying the phoenix_config.txt file value use_dns_lookup=no and restarting the node services. By default, DNS lookups are already disabled.

DNS

FortiSIEM can be configured to perform DNS resolution of parsed IP address fields as part of event processing and enrichment. This allows the analyst to see the domain name of the address when reviewing logs and performing investigations.

If enabled, DNS resolution is performed by the ingesting node as the event is processed. This could be a collector at a remote site in a distributed solution. When using this feature, design the supporting DNS services to provide resolution of addresses received by the system at the point of ingestion, and ensure the nodes are configured with the correct DNS server addresses to allow the request to be sent.

Failing to provide suitable DNS services will result in many failed DNS requests on the node, which can impact performance. If the deployment scenario prevents adequate DNS services being deployed and the node is experiencing DNS based performance issues, disable DNS for the entire node by modifying the phoenix_config.txt file value use_dns_lookup=no and restarting the node services. By default, DNS lookups are already disabled.