tsale / EDR-Telemetry

This project aims to compare and evaluate the telemetry of various EDR products.
1.5k stars 142 forks source link

DNS queries for Crowdstrike #1

Closed mthcht closed 1 year ago

mthcht commented 1 year ago

I am collecting telemetry data in Splunk for CrowdStrike, and I have "vertex_type=domain", it should include DNS queries (even with the sampling)

tsale commented 1 year ago

Thanks @mthcht! I had a look at the documentation provided by a contributor and it seems that I missed this. I’ll fix asap.