elastic / elastic/integrations
Agent | Local DNS Processing
Open
enhancement
Integration:panw
Integration:suricata
Team:Security-Deployment and Devices
- Dominant language
- Handlebars
- Stars
- 333
- Forks
- 647
- Avg merge
- 2d 17h
- Merged PRs (30d)
- 225
Description
Many of our integrations including Palo Alto, Suricata (presumably all firewall/IDS integration) leverage the DNS processor within our ingest node pipelines. This is posing a problem for cloud customers who cannot enrich events (i.e. DNS reverse lookups) of on-prem hosts before shipping to the cloud.
Is moving the DNS processing from ingest node to the agent an option?
Providing optionality as to where processing takes place (regardless of processor) is a longer term goal, this particular is intended to focus solely on tackling the DNS issue.
Contributor guide
Assessment
This issue has not been assessed yet.