Document toolboxDocument toolbox

dns.neustar

Introduction

The tags beginning with dns.neustar identify events generated by DNS services provided by Neustar.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as dns.neustar. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Neustar UltraDNS

dns.neustar.ultradns.config_audit

dns.neustar.ultradns.config_audit

dns.neustar.ultradns.volume_report

dns.neustar.ultradns.volume_report

dns.neustar.ultradns.zone_volume_report

dns.neustar.ultradns.zone_volume_report

For more information, read more About Devo tags.

Table structure

These are the fields displayed in these tables:

dns.neustar.ultradns.config_audit

Field

Type

Field transformation

Source field name

Extra fields

Field

Type

Field transformation

Source field name

Extra fields

eventdate

timestamp

 

 

 

hostname

str

 

 

 

object_type

str

 

 

 

change_type

str

 

 

 

object

str

 

 

 

user

str

 

 

 

ip

ip4

 

 

 

change_time

timestamp

 

 

 

account

str

 

 

 

detail__changes__name_str

str

join(detail__changes__name, ',')

detail__changes__name

 

detail__changes__from_str

str

join(detail__changes__from, ',')

detail__changes__from

 

detail__changes__to_str

str

join(detail__changes__to, ',')

detail__changes__to

 

hostchain

str

 

 

✓

tag

str

 

 

✓

rawMessage

str

 

 

✓

dns.neustar.ultradns.volume_report

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

year

str

 

month

str

 

current_day

str

 

response_month_to_day

int8

 

response_month_to_day_7d_average

int8

 

response_month_to_day_30d_average

int8

 

ttl_average

int8

 

response_daily

int4

 

hostchain

str

 ✓

tag

str

 ✓

rawMessage

str

 ✓

dns.neustar.ultradns.zone_volume_report

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

zone_name

str

 

account_name

str

 

start_date

timestamp

 

end_date

timestamp

 

response_total

int4

 

tcp_total

int4

 

udp_total

int4

 

ipv4_total

int4

 

ipv6_total

int4

 

ipv4tcp_total

int4

 

ipv4udp_total

int4

 

ipv6tcp_total

int4

 

ipv6udp_total

int4

 

record_a

int4

 

record_a6

int4

 

record_aaaa

int4

 

record_any

int4

 

record_axfr

int4

 

record_cert

int4

 

record_cname

int4

 

record_dlv

int4

 

record_dnskey

int4

 

record_hinfo

int4

 

record_ipseckey

int4

 

record_ixfr

int4

 

record_loc

int4

 

record_mf

int4

 

record_naptr

int4

 

record_mx

int4

 

record_ns

int4

 

record_nsec

int4

 

record_nsec3

int4

 

record_nsec3_param

int4

 

record_rp

int4

 

record_ptr

int4

 

record_rrsig

int4

 

record_soa

int4

 

record_spf

int4

 

record_srv

int4

 

record_sshfp

int4

 

record_ta

int4

 

record_tsig

int4

 

record_tkey

int4

 

record_txt

int4

 

hostchain

str

 ✓

tag

str

 ✓

rawMessage

str

 ✓