elastic / elastic/integrations

Agent | Local DNS Processing

Open
#2,532 9 comments 7 reactions 0 assignees View on GitHub
enhancement Integration:panw Integration:suricata Team:Security-Deployment and Devices
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
2d 17h
Merged PRs (30d)
225

Description

Many of our integrations including Palo Alto, Suricata (presumably all firewall/IDS integration) leverage the DNS processor within our ingest node pipelines. This is posing a problem for cloud customers who cannot enrich events (i.e. DNS reverse lookups) of on-prem hosts before shipping to the cloud.

Is moving the DNS processing from ingest node to the agent an option?

Providing optionality as to where processing takes place (regardless of processor) is a longer term goal, this particular is intended to focus solely on tackling the DNS issue.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.