A Windows DNS content pack for graylog.
Switch branches/tags
Nothing to show
Clone or download
Latest commit 516af50 Mar 11, 2016
Failed to load latest commit information.
LICENSE license update Sep 23, 2015
README.md Warn about gelf 1.1 Mar 11, 2016
content_pack.json add new REPLACE extractor WINDNS_NAME Dec 9, 2015


Windows DNS Content Pack

This version requires Graylog 1.3 minimum, check branches for previous versions.

(Tested with nxLog/Windows 2008 R2/Graylog 1.3)

Newer versions of nxLog with Gelf 1.1 support require an additional parameter for the gelf module "ShortMessageLength -1"


  • Input (WinLogs-gelf - GELF/UDP/5414)
  • Extractors (WinDNS_Debug_Log, WinDNS_Name)
  • GROK Patterns
  • Dashboard (WinDNS Summary)


  • Graylog 1.3 (due to REPLACE extractor)
  • Windows DNS server configured for "Log packets for debugging" & "Packet direction: Incoming"
  • A GELF capable log exporter/collector such as nxlog or Graylog Collector monitoring the log file path
  • Create an ES template to force the ThreadID field type to "String", otherwise ES may dynamically map the field type as INT which would cause indexing errors later on when an alphanumeric ThreadID comes around.
curl -XPUT localhost:9200/_template/graylog -d '

NXLog Configuration Example

define ROOT C:\Program Files (x86)\nxlog

Moduledir %ROOT%\modules
CacheDir %ROOT%\data
Pidfile %ROOT%\data\nxlog.pid
SpoolDir %ROOT%\data
LogFile %ROOT%\data\nxlog.log

<Extension gelf>
    Module xm_gelf
    ShortMessageLength -1

<Input dns>
    Module  im_file
    File  "C:\dns.txt"
    SavePos TRUE
    InputType LineBased

<Output out> 
    Module      om_udp
    Host        graylog.server.com
    Port        5414
    OutputType  GELF

<Route 2>
    Path        dns => out