-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update error codes for Sysmon DNS #16040
Update error codes for Sysmon DNS #16040
Conversation
Pinging @elastic/siem (Team:SIEM) |
var dnsQueryStatusCodes = { | ||
"0": "SUCCESS", | ||
"2329": "DNS_ERROR_RCODE_FORMAT_ERROR", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'm not sure where I got these codes from originally because they don't seem to exist 🤷♂ .
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is really weird. The ID for all this removed error codes is in hex, while they have been re-added in decimal. For example:
- "2330": "DNS_ERROR_RCODE_NXRRSET",
+ "9008": "DNS_ERROR_RCODE_NXRRSET",
DNS_ERROR_RCODE_NXRRSET 9008 (0x2330)
And all the errors where the hex code included an non-decimal hex digit were missing.
jenkins, test this |
This generates a list of error numbers / symbolic names from winerror.h. I included errors that began with "DNS_" and some additional error codes as reported in elastic#15685. Fixes elastic#15685
8d6cf58
to
281ff90
Compare
var dnsQueryStatusCodes = { | ||
"0": "SUCCESS", | ||
"2329": "DNS_ERROR_RCODE_FORMAT_ERROR", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is really weird. The ID for all this removed error codes is in hex, while they have been re-added in decimal. For example:
- "2330": "DNS_ERROR_RCODE_NXRRSET",
+ "9008": "DNS_ERROR_RCODE_NXRRSET",
DNS_ERROR_RCODE_NXRRSET 9008 (0x2330)
And all the errors where the hex code included an non-decimal hex digit were missing.
This generates a list of error numbers / symbolic names from winerror.h. I included errors that began with "DNS_" and some additional error codes as reported in elastic#15685. Fixes elastic#15685 (cherry picked from commit 8f5d755)
This generates a list of error numbers / symbolic names from winerror.h. I included errors that began with "DNS_" and some additional error codes as reported in elastic#15685. Fixes elastic#15685 (cherry picked from commit 8f5d755)
This generates a list of error numbers / symbolic names from winerror.h. I included errors that began with "DNS_" and some additional error codes as reported in #15685.
Fixes #15685