1. Describe your incident:
I’m sending logs from our DNS server to Graylog and these logs contain the requested domain and replies (CNAME entries, A entries, etc).
Is there any chance I can load these into a lookup table or something similar? I’d like to reuse them later with our firewall logs that only show destination IP addresses right now but troubleshooting would be so much easier if I would see destination IP addresses and domain name of the ip address.
So can I use information from earlier events to add information to later events?
2. Describe your environment:
Graylog 4.3.15
Ubuntu 20.04.6 LTS
3. What steps have you already taken to try and solve the problem?
Google, Forum search
4. How can the community help?
Give me a hint or guide me to manual/posts that I’m not smart enough to find when I searched.