dns.aws
Introduction
The tags beginning with dns.aws
identify events generated by DNS services belonging to Amazon Web Services.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as dns.aws
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
AWS Route 53 |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
dns.aws.route53
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
logFormatVersion |
|
|
queryTimestamp |
|
|
hostedZoneID |
|
|
queryName |
|
|
queryType |
|
|
responseCode |
|
|
layer4Protocol |
|
|
route53EdgeLocation |
|
|
resolverIPAddress |
|
|
EDNSClientSubnet |
|
|
id |
|
|
timestamp |
|
|
srcPort |
|
|
queryClass |
|
|
answers |
|
|
vpcID |
|
|
region |
|
|
srcIds |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |