Microsoft-Windows-DNS-Server-Service
497 events across 1 channel
Event ID 2 —
Message
Fields
| Name | Description |
|---|---|
Name | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 2
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854779904
time_created: '2022-04-07T16:56:30.613142+00:00'
event_record_id: 30
correlation: {}
execution:
process_id: 2320
thread_id: 2848
channel: DNS Server
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: DNS_EVENT_STARTUP_OK
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 3 —
Message
Fields
| Name | Description |
|---|---|
Name | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 3
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854779904
time_created: '2022-04-07T08:38:25.939614+00:00'
event_record_id: 22
correlation: {}
execution:
process_id: 2780
thread_id: 2212
channel: DNS Server
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: DNS_EVENT_SHUTDOWN
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4 —
Message
Fields
| Name | Description |
|---|---|
Name | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 4
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775824
time_created: '2022-04-07T08:31:21.436717+00:00'
event_record_id: 21
correlation: {}
execution:
process_id: 2780
thread_id: 4540
channel: DNS Server
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: DNS_EVENT_ZONE_LOAD_COMPLETE
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10 — The DNS server could not start because it is dependent on the NTDS service which is not started.
Message
Event ID 11 — The DNS server could not register dependency on %1 service.
Message
Fields
| Name | Description |
|---|---|
serviceName | — |
__binLength | — |
binary | — |
Event ID 111 — The DNS server could not create a thread.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 131 — DNS Server Zone Transfer
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 140 — DNS Server Service Status
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 150 —
Message
Fields
| Name | Description |
|---|---|
Name | — |
Data | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 150
version: 0
level: 2
task: 0
opcode: 0
keywords: 9223372036854808576
time_created: '2021-05-18T21:23:27.038306+00:00'
event_record_id: 11659
correlation: {}
execution:
process_id: 3880
thread_id: 444
channel: DNS Server
computer: rootdc1.offsec.lan
security:
user_id: S-1-5-18
event_data:
Name: DNS_EVENT_PLUGIN_INIT_FAILED
Data:
Name: param1
Value: .\mimilib.dll
Binary: fgAAAA==
message: ''
Sigma Rules
- DNS Server Error Failed Loading the ServerLevelPluginDLL
Detects a DNS server error in which a specified plugin DLL (in registry) could not be loaded
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 403 — The DNS server could not create a Transmission Control Protocol (TCP) socket.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 404 —
Message
Fields
| Name | Description |
|---|---|
Name | — |
Data | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 404
version: 0
level: 2
task: 0
opcode: 0
keywords: 9223372036855824384
time_created: '2022-04-07T16:59:58.007502+00:00'
event_record_id: 34
correlation: {}
execution:
process_id: 2320
thread_id: 4240
channel: DNS Server
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: DNS_EVENT_CANNOT_BIND_TCP_SOCKET
Data:
Name: param1
Value: 169.254.142.31
Binary: QScAAA==
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 405 — The DNS server could not listen on Transmission Control Protocol (TCP) socket for address %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 406 — The DNS server could not create a User Datagram Protocol (UDP) socket.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 407 —
Message
Fields
| Name | Description |
|---|---|
Name | — |
Data | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 407
version: 0
level: 2
task: 0
opcode: 0
keywords: 9223372036855824384
time_created: '2022-04-07T16:59:58.007280+00:00'
event_record_id: 32
correlation: {}
execution:
process_id: 2320
thread_id: 4240
channel: DNS Server
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: DNS_EVENT_CANNOT_BIND_UDP_SOCKET
Data:
Name: param1
Value: 169.254.142.31
Binary: QScAAA==
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 408 —
Message
Fields
| Name | Description |
|---|---|
Name | — |
Data | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 408
version: 0
level: 2
task: 0
opcode: 0
keywords: 9223372036855824384
time_created: '2022-04-07T16:59:58.007504+00:00'
event_record_id: 35
correlation: {}
execution:
process_id: 2320
thread_id: 4240
channel: DNS Server
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: DNS_EVENT_OPEN_SOCKET_FOR_ADDRESS
Data:
Name: param1
Value: 169.254.142.31
Binary: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 409 — The DNS server list of restricted interfaces contains IP addresses that are not configured for use at the server computer.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 410 — The DNS server list of restricted interfaces does not contain a valid IP address for the server computer.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 411 — The DNS server has bound one or more socket pool sockets to port numbers from port exclusion range %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 414 — The DNS server computer currently does not have a DNS domain name.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 500 — The DNS server has detected that the zone %1 has invalid or corrupted registry data.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 501 — The DNS server has detected that the zone %1 has a missing or corrupted zone type in registry data.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 502 — The DNS server has detected that for the primary zone %1 its has no zone file name stored in registry data.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 503 — The DNS server has detected that the secondary zone %1 has no master IP addresses in registry data.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 504 — The DNS server could not create zone %1 from registry data.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 505 — The DNS server zone %1 has invalid or corrupted registry data for %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 506 — The DNS server has invalid or corrupted registry parameter %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 507 — The DNS server encountered invalid or corrupted forwarder parameters in registry data.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 706 — The DNS server does not have a cache or other database entry for root name servers.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 707 — The DNS server is not root authoritative and no root hints were specified in the cache.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 708 —
Message
Fields
| Name | Description |
|---|---|
Name | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 708
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854779904
time_created: '2022-04-07T16:56:30.583997+00:00'
event_record_id: 29
correlation: {}
execution:
process_id: 2320
thread_id: 2848
channel: DNS Server
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: DNS_EVENT_CACHING_SERVER_ONLY
Binary: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 709 — The DNS server has moved the AD-integrated root hint data for all DNS servers in this domain to the %1 directory partition.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 710 — An administrator has changed the type and zone storage options of zone %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 711 — An administrator has changed the type and/or Active Directory location of zone %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 712 — An administrator has changed the zone storage options for zone %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 713 — An administrator has moved the zone %1 to a new location in Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 768 — The DNS server has loaded the scope %1 of zone %2 from file %3 on server %4.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
VirtualizationID | — |
Event ID 769 —
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
VirtualizationID | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 769
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775824
time_created: '2022-04-07T08:31:20.801344+00:00'
event_record_id: 19
correlation: {}
execution:
process_id: 2780
thread_id: 2212
channel: DNS Server
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
param1: sigma.fr
param2: 'NULL'
param3: WIN-FPV0DSIC9O6.sigma.fr
VirtualizationID: .
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 770 —
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 770
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854808576
time_created: '2021-05-18T21:33:49.548066+00:00'
event_record_id: 11684
correlation: {}
execution:
process_id: 180
thread_id: 4116
channel: DNS Server
computer: rootdc1.offsec.lan
security:
user_id: S-1-5-18
event_data:
param1: C:\TOOLS\Mimikatz-fev-2020\mimilib.dll
param2: rootdc1.offsec.lan
message: ''
Sigma Rules
- DNS Server Error Failed Loading the ServerLevelPluginDLL
Detects a DNS server error in which a specified plugin DLL (in registry) could not be loaded
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 771 —
Message
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 771
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854808576
time_created: '2021-05-18T21:33:49.548062+00:00'
event_record_id: 11683
correlation: {}
execution:
process_id: 180
thread_id: 4116
channel: DNS Server
computer: rootdc1.offsec.lan
security:
user_id: S-1-5-18
event_data: {}
message: ''
Sigma Rules
- DNS Server Error Failed Loading the ServerLevelPluginDLL
Detects a DNS server error in which a specified plugin DLL (in registry) could not be loaded
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 772 — The V2 plugin interface has been implemented in server level plugin DLL.
Message
Event ID 773 — The V3 plugin interface to select scopes of a zone has been implemented in server level plugin DLL.
Message
Event ID 774 — The RecursionScope plugin interface to select scope of the DNS server has been implemented in server level plugin DLL.
Message
Event ID 775 — The CacheScope plugin interface to select scope of the DNS cache has been implemented in server level plugin DLL.
Message
Event ID 776 — The DNS server has started to unsign the zone %1 on server %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 777 — The DNS server encountered an error while unsigning the zone %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 784 — The key signing key with GUID %1 of zone %2 has moved to stage %3 of rollover.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 785 — The zone signing key with GUID %1 of zone %2 has moved to stage %3 of rollover.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 786 — The DNS server is being started in authoritative-cache mode %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 787 — Negative caching has been disabled on the server %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 788 — The DNS server has loaded the scope %1 of server %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 789 — The DNS server has loaded the virtualization instance.
Message
Fields
| Name | Description |
|---|---|
VirtualizationID | — |
Event ID 790 — The EDNS option code %1 for scope transaction is invalid or conflicts with the configuration of another EDNS option.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 791 — The ScopeOptionValue has been set to %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 792 — Failed to load server level policy %1 of server %2.
Message
Fields
| Name | Description |
|---|---|
Policy | — |
Server | — |
Event ID 793 — Failed to load zone level policy %1 of zone %3 on server %2.
Message
Fields
| Name | Description |
|---|---|
Policy | — |
Server | — |
Zone | — |
Event ID 794 — Failed to load zone level policy %1 of zone %3 on server %2.
Message
Fields
| Name | Description |
|---|---|
Policy | — |
Server | — |
Zone | — |
Scope | — |
Event ID 795 — Failed to load server level policy %1 on server %2.
Message
Fields
| Name | Description |
|---|---|
Policy | — |
Server | — |
Scope | — |
Event ID 796 — Failed to load the client subnet %1.
Message
Fields
| Name | Description |
|---|---|
ClientSubnetRecord | — |
Event ID 797 — Failed to load a server level policy of server %1.
Message
Fields
| Name | Description |
|---|---|
Server | — |
Event ID 798 — Failed to load a zone level policy of zone %2 on server %1.
Message
Fields
| Name | Description |
|---|---|
Server | — |
Zone | — |
Event ID 799 — Failed to load client subnets on server %1.
Message
Fields
| Name | Description |
|---|---|
Server | — |
Event ID 800 — The zone %1 is configured to accept updates but the A record for the primary server in the zone's SOA record is not available on this DNS server.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 801 — Failed to load Response Rate Limiting parameters on server %1.
Message
Fields
| Name | Description |
|---|---|
Server | — |
Event ID 802 — Failed to enable Response Rate Limiting on server %1.
Message
Fields
| Name | Description |
|---|---|
Server | — |
Event ID 803 — The EDNS option code %1 for the virtualization instance option is invalid or conflicts with the configuration of another EDNS option.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 804 — Failed to load virtualization instance.
Message
Fields
| Name | Description |
|---|---|
VirtualizationID | — |
Event ID 805 — Failed to read the virtualization instance from registry.
Message
Event ID 806 — The VirtualizationInstanceOptionValue has been set to %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 807 — The DNS server received indication that scope %1 of zone %2 was deleted from the Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 808 — The V6 plugin interface has been implemented in server level plugin DLL.
Message
Event ID 809 — The EDNS option code %1 for the DNS data tag is invalid or conflicts with the configuration of another EDNS option.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 817 — The DataTagOptionValue has been set to %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 818 — The throttle plugin interface has been implemented in server level plugin DLL.
Message
Event ID 819 — The CorrelationTagOptionValue has been set to %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 820 — The logging plugin interface has been implemented in server level plugin DLL.
Message
Event ID 821 — The init query plugin interface has been implemented in server level plugin DLL.
Message
Event ID 822 — Successfully started HTTP server for DNS-over-HTTPS (DoH) server.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 823 — The DNS server could not initialize the HTTP server for DNS-over-HTTPS (DoH) and failed with error code %1lu.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 824 — The DNS server could not create the HTTP server session for DNS-over-HTTPS (DoH) and failed with error code %1lu.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 825 — The DNS server could not register the URL for the DNS-over-HTTPS (DoH) server and failed with error code %1lu.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 826 — The DNS server could not create the HTTP request queue for DNS-over-HTTPS (DoH) and failed with error code %1lu.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 827 — The configuration for DNS-over-HTTPS (DoH) server are.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 828 — The DNS-over-HTTPS (DoH) server has shut down gracefully.
Message
Event ID 829 — The DNS-over-HTTPS (DoH) server has shut down due to an error and failed with error code %1.
Message
Fields
| Name | Description |
|---|---|
errorCode | — |
Event ID 1000 — The DNS server could not open the file %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 1001 — The DNS server could not map file %1 to memory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 1003 — DNS Server RPC Protocol Initialization
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1004 — The DNS server could not find or open zone file %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 1008 — The DNS server was unable to create the path for file %1 in directory %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1200 — The DNS server could not find or open boot file %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 1201 — The DNS server could not create zone %1 specified in file %2 at line %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1202 — The DNS server encountered an unsupported 'directory' directive in the server boot file %1 at line %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1203 — The DNS server encountered a 'forwarders' directive in with no forwarding addresses in file %1 at line %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1205 — The DNS server encountered an unknown boot option %1 in file %2 at line %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1206 — DNS server encountered missing database directory name, in file %1, line %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1501 — The DNS server could not parse zone file %1 for zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1502 — The DNS server could not parse the token ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1503 — The DNS server could not parse the zone file %1 at line %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1504 — The DNS server could not parse an unexpected token ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1505 — The DNS server unexpected end of line, in zone file %1 at line %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1506 — The DNS server encountered invalid token ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1507 — The DNS server encountered invalid class token ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1508 — The DNS server is ignoring an invalid resource record in zone file %1 at line %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1520 — The DNS server encountered the unknown directive '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1521 — The DNS server encountered the unsupported directive '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1522 — The DNS server encountered the obsolete directive '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1523 — The DNS server encountered the directive '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1524 — DNSSEC signatures with key tag %1, associated with records in zone %2, have expired.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1525 — DNSSEC signatures with key tag %1, associated with records in zone %2, will expire on %3 (UTC time).
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1540 — The DNS server unable to create domain node.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1541 — The DNS server encountered invalid domain name ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1542 — The DNS server encountered invalid domain name ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 1543 — The DNS server encountered domain name ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 1544 — The DNS server encountered an invalid "@" token ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1545 — The DNS server encountered a name outside of the specified zone in zone file %1 at line %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1546 — The DNS server encountered an invalid name server (NS) resource record in zone file %1 at line %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1547 — The DNS server encountered an invalid host (A) resource record in zone file %1 at line %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1600 — The DNS server encountered an unknown or unsupported resource record (RR) type %1 in zone file %2 at line %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1601 — DNS server encountered the obsolete record type %1 in database file %2, line %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1602 — The DNS server encountered an invalid SOA (Start Of Authority) resource record (RR) in file %1 at line %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1610 — The DNS server encountered a resource record (RR) in the zone file %1 at line %2 for a domain name with an existing CNAME (alias) RR.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1611 — The DNS server encountered a CNAME (alias) resource record (RR) in zone file %1 at line %2 for a domain name with existing RRs.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1612 — The DNS server encountered an alias (CNAME or DNAME) resource record (RR) in zone file %1 at line %2 that forms an alias loop with another alias RR...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1613 — The DNS server encountered an invalid preference value ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1614 — The DNS server encountered a token ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1616 — The DNS server encountered a text string ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1617 — The DNS server encountered an invalid IP address ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1618 — The DNS server encountered an invalid IPv6 address ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1619 — The DNS server could not find protocol ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1620 — The DNS server could not find the service ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1621 — The DNS server encountered the port ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1650 — The DNS server encountered invalid WINS record in file %1, line %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1651 — The DNS server encountered an invalid WINS reverse lookup (WINSR) resource record (RR) in file %1 at line %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 1654 — The DNS server encountered an unknown WINS-to-DNS mapping flag %1 in file %2 at line %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 1656 — The DNS server encountered a WINS reverse lookup (WINSR) resource record (RR) without a domain specified for resulting names in zone file %1 at lin...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 2001 — The DNS server is now booting from the registry or directory.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 2002 — The DNS server has written a new version of the boot file.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 2003 — The DNS server encountered an error writing current configuration back to boot file.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 2005 — The DNS server has been reconfigured to boot from a boot file.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 2200 — The DNS server could not open a registry key.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 2202 — The DNS server could not write a registry key.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 2203 — The DNS server could not delete a registry key.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 2204 — The registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters\.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 2501 — The DNS server has completed a scavenging cycle: Visited Zones = %1, Visited Nodes = %2, Scavenged Nodes = %3, Scavenged Records = %4.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
__binLength | — |
binary | — |
Event ID 2502 — The DNS server has completed a scavenging cycle but no nodes were visited.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 2630 — DNS Server Configuration
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 2631 —
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 2631
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854779904
time_created: '2022-04-07T08:13:51.349882+00:00'
event_record_id: 2
correlation: {}
execution:
process_id: 2208
thread_id: 4676
channel: DNS Server
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
param1: DNS server root hints
param2: DNS server forwarders
param3: DNS resolver
param4: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 3150 —
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 3150
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775824
time_created: '2022-04-07T08:14:09.727051+00:00'
event_record_id: 5
correlation: {}
execution:
process_id: 2208
thread_id: 7088
channel: DNS Server
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
param1: '2'
param2: sigma.fr
param3: sigma.fr.dns
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 3151 — The DNS server unable to write zone file %1 for zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 3152 — The DNS server was unable to open file %1 for write.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 3153 — The DNS server encountered an error writing to file.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 3162 — The DNS server encountered an unknown protocol writing a well known service (WKS) resource record to the zone file.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 3163 — While writing a well known service (WKS) record to the zone file, the DNS server encountered a port number that is not associated with a known serv...
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 4000 —
Message
Fields
| Name | Description |
|---|---|
Name | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 4000
version: 0
level: 2
task: 0
opcode: 0
keywords: 9223372036854841344
time_created: '2022-04-07T16:54:41.266037+00:00'
event_record_id: 26
correlation: {}
execution:
process_id: 2320
thread_id: 2848
channel: DNS Server
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: DNS_EVENT_DS_OPEN_FAILED
Binary: KiMAAA==
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4001 — The DNS server was unable to open zone %1 in the Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 4002 — The DNS server was unable to add zone %1 to the Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 4003 — The DNS server was unable to delete zone %1 in the Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 4004 — The DNS server was unable to complete directory service enumeration of zone %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 4005 — The DNS server received indication that zone %1 was deleted from the Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 4006 — The DNS server could not load the records for the DNS name %1 found in the Active Directory integrated zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 4007 —
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 4007
version: 0
level: 2
task: 0
opcode: 0
keywords: 9223372036854906880
time_created: '2022-04-07T16:55:35.860770+00:00'
event_record_id: 28
correlation: {}
execution:
process_id: 2320
thread_id: 2848
channel: DNS Server
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
param1: _msdcs.sigma.fr
param2: ForestDnsZones.sigma.fr
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4010 — The DNS server was unable to create a resource record for %1 in zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 4011 — The DNS server was unable to add or write an update of domain name %1 in zone %2 to the Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 4012 — The DNS server timed out attempting to write resource records to the Active Directory at %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 4013 —
Message
Fields
| Name | Description |
|---|---|
Name | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 4013
version: 0
level: 3
task: 0
opcode: 0
keywords: 9223372036854906880
time_created: '2022-04-07T16:53:29.562920+00:00'
event_record_id: 24
correlation: {}
execution:
process_id: 2320
thread_id: 2848
channel: DNS Server
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: DNS_EVENT_DS_OPEN_WAIT
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4014 — The DNS server was unable to initialize Active Directory security interfaces.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 4015 —
Message
Fields
| Name | Description |
|---|---|
Name | — |
Data | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 4015
version: 0
level: 2
task: 0
opcode: 0
keywords: 9223372036854906880
time_created: '2022-04-07T16:59:32.615235+00:00'
event_record_id: 31
correlation: {}
execution:
process_id: 2320
thread_id: 764
channel: DNS Server
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: DNS_EVENT_DS_INTERFACE_ERROR
Data:
Name: param1
Value: ''
Binary: UQAAAA==
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4016 — The DNS server timed out attempting an Active Directory service operation on %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 4017 — The DNS server was unable to load or create the DnsAdmins group.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 4018 — The DNS server was unable to begin background loading of Active Directory-integrated zones.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 4019 — The DNS server attempted to load the Active Directory-integrated zone %1 in the background but there was an error during load.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 4020 — The DNS server is now starting to load zone %1 in the background.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 4021 — The DNS server has completed background loading of zone %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 4400 — The DNS server is experiencing high SOA query load.
Message
Event ID 4401 — The DNS server is experiencing high SOA query load.
Message
Event ID 4500 —
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 4500
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854906880
time_created: '2022-04-07T08:15:14.778973+00:00'
event_record_id: 14
correlation: {}
execution:
process_id: 2732
thread_id: 4188
channel: DNS Server
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
param1: ForestDnsZones.sigma.fr
param2: DC=ForestDnsZones,DC=sigma,DC=fr
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4501 — The DNS Application Directory Partition %1 was deleted.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 4502 — The DNS added the local Active Directory to the replication scope of Application Directory Partition %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 4503 — The DNS removed the local Active Directory from the replication scope of Application Directory Partition %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 4510 — The DNS server was unable to connect to the domain naming FSMO %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 4511 — The zone %1 was not successfully saved to the new directory partition as %2 due to an error deleting the zone from the old directory partition as %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 4512 — The DNS server was unable to create the built-in directory partition %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 4513 — The DNS server detected that it is not enlisted in the replication scope of the directory partition %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 4514 — The DNS server detected that it is not enlisted in the replication scope of the directory partition %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 4515 — The zone %1 was previously loaded from the directory partition %2 but another copy of the zone has been found in directory partition %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 4520 — The DNS server encountered error %1 building the zone list from Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 4521 — The DNS server encountered error %1 attempting to load zone %2 from Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 4522 — The DNS server has deleted all records for a corrupt DNS node from Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4523 — The DNS server has detected that the application directory partition %1 is replicating onto this domain controller.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4524 — DNS Server Autoconfiguration
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 5051 — The DNS server is using a large amount of memory.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5105 — The DNS server attempted to cache an CNAME (alias) resource record for the domain node.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5106 — The DNS server attempted to cache an CNAME (alias) resource record (RR) for a domain name with existing RRs.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5107 — The DNS server created CNAME (alias) loop caching CNAME resource records (RRs).
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5108 — The DNS server created an CNAME (alias) loop loading CNAME at %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 5500 — The DNS server received a bad DNS query from %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 5501 — The DNS server encountered a bad packet from %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 5502 — The DNS server received a bad TCP-based DNS message from %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 5504 — The DNS server encountered an invalid domain name in a packet from %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 5505 — The DNS server encountered a domain name exceeding the maximum length in the packet from %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 5506 — The DNS server encountered an invalid domain name offset in a packet from %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 5507 — The DNS server encountered a name offset exceeding the packet length from %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 5508 — The DNS server encountered a packet name exceeding the maximum label count from %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 5509 — The DNS server encountered an invalid DNS update message from %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 5510 — The DNS server encountered an invalid response message from %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 5511 — The DNS server encountered a name with a label whose length exceeds the maximum of 63 bytes from %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 6000 — The DNS server started transfer of version %1 of zone %2 to the DNS server at %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 6001 — The DNS server successfully completed transfer of version %1 of zone %2 to the DNS server at %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 6002 — The transfer of version %1 of zone %2 by the DNS server was aborted by the server at %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 6003 — The DNS server received a request from %1 for a UDP-based transfer of the entire zone.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 6004 —
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 6004
version: 0
level: 3
task: 0
opcode: 0
keywords: 9223372036855300096
time_created: '2020-07-11T12:58:57.451062+00:00'
event_record_id: 343
correlation: {}
execution:
process_id: 1764
thread_id: 2284
channel: DNS Server
computer: rootdc1.offsec.lan
security:
user_id: S-1-5-18
event_data:
param1: 10.23.23.9
param2: hacking-zone.lan.
message: ''
Sigma Rules
- Failed DNS Zone Transfer
Detects when a DNS zone transfer failed.
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 6520 — Zone %1 was updated to version %2 of the zone as provided from the master server at %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 6521 — Zone %1 is synchronized with version %2 of the zone as provided from the master server at %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 6522 — A more recent version, version %1 of zone %2 was found at the DNS server at %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 6523 — Zone %1 failed zone refresh check.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 6524 — Invalid response from master DNS server at %2 during attempted zone transfer of zone %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 6525 — A zone transfer request for the secondary zone %1 was refused by the master DNS server at %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 6526 — Zone %1 version %2 is newer than version %3 on DNS server at %4.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
__binLength | — |
binary | — |
Event ID 6527 — Zone %1 expired before it could obtain a successful zone transfer or update from a master server acting as its source for the zone.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 6528 — The scope %1 of zone %2 expired before it could obtain a successful zone transfer or update from a master server acting as its source for the zone.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 6529 — The operation for zone %1 is not complete.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 6530 — During transfer of zone %1 from master at %2, the DNS server received a resource record (RR) for domain node %3 at which an CNAME (alias) RR was al...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 6531 — During transfer of zone %1 from master at %2, the DNS server received a CNAME (alias) resource record (RR) for domain node %3 for which other recor...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 6532 — During transfer of zone %1 from master at %2, the DNS server received a CNAME (alias) resource record (RR) for domain node %3 which would form an C...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 6533 — The DNS server could not create a zone transfer thread.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 6534 — Failed transfer of zone %1 from DNS server at %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 6535 — The master DNS server at %2 responded to IXFR (Incremental Zone Transfer) request for zone %1 with an invalid (FORMAT ERROR) response.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 6536 — Invalid IXFR (Incremental Zone Transfer) response from master DNS server at %2 during attempted incremental transfer of zone %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7050 — The DNS server recv() function failed.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 7051 — The DNS server recvfrom() function failed.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 7052 — The DNS server send() function failed.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 7053 — The DNS server sendto() function failed.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 7054 — The DNS server select() function failed.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 7055 — The DNS server accept() function failed.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 7056 — The DNS server GetQueuedCompletionStatus() function failed.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 7060 — The DNS server could not connect to DNS server at %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 7062 — The DNS server encountered a packet addressed to itself on IP address %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7500 — The DNS server failed to process a packet from %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 7502 — The DNS server was unable to service a client request due a shortage of available memory.
Message
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 7503 — The DNS server could not allocate memory for resource record %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 7504 — DNS Server WINS NetBIOS Initialization
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 7600 — The global query block list is a feature that prevents attacks on your network by blocking DNS queries for specific host names.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 7616 — The TrustAnchors zone could not be loaded.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 7632 — The DNSSEC trust point %1 is available for DNSSEC validation.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7633 — The DNSSEC trust point %1 is available for DNSSEC validation.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 7634 — The DNSSEC trust point %1 is not available for DNSSEC validation, because a valid DNSKEY record that matches the provided DS trust anchor(s) has no...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7635 — The DNSSEC trust point %1 will be deleted after %2 because it has no valid trust anchors.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7636 — The DNSSEC trust point %1 has been deleted because it has no valid or revoked trust anchors.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 7637 — The DS record with the key tag %2 at the trust point %1 will be replaced with a DNSKEY trust anchor when a matching DNSKEY record is found during t...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7638 — The DNSKEY with the key tag %2 at the trust point %1 is now a valid trust anchor for use in DNSSEC validations.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7639 — The trust anchor with the key tag %2 at the trust point %1 has been removed from the authoritative server without being revoked.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7640 — The DNSKEY with the key tag %2 at the trust point %1 has been marked as revoked by the authoritative server.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7641 — The DNSKEY with the key tag %2 at the trust point %1 will become a trust anchor after %3, if it is consistently present on the authoritative server.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 7642 — The DS record with the key tag %2 at the trust point %1 does not correspond to a valid trust anchor.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7643 — The %3 with the key tag %2 at the trust point %1 has been deleted.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 7644 — The active refresh query for the DNSKEY records at the trust point %1 has failed (%2).
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 7645 — The active refresh query for the DNSKEY records at the trust point %1 has succeeded.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7646 — The zone %1 is now signed with DNSSEC.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 7647 — The zone %1 is no longer signed with DNSSEC.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 7648 — The DNS server has detected that it is no longer the Key Master for zone %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7649 — The DNS server has successfully assumed Key Master responsibilities for zone %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7650 — The DNS server has started signing the zone %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 7652 — The DNS server encountered an error while signing the zone %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7653 — The DNS server has detected that zone signing parameters for zone %1 have been changed.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7654 — The DNS server was unable to sign zone data changed by dynamic update at node %1 in zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 7655 — The DNS server was unable to sign zone data changed by a scavenging update to remove stale records at node %1 in zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 7656 — The DNS server was unable to sign zone changes replicated from another domain controller at node %1 in zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 7657 — The DNS server was unable to refresh signatures at node %1 in zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 7658 — The DNS server was unable to complete re-signing of the zone %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7659 — The DNS server was unable to sign new DS records from the child zone at node %1 in zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 7660 — The DNS server was unable to validate new DS records from the child zone at node %1 in zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7661 — The DNS server was unable to sign an administrative update at node %1 in zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 7662 — The DNS server will not be able to automatically refresh the DS record set at node %1 in zone %2 because this DNS server does not support all DS an...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7663 — The DNS server was unable to sign the zone %1 because it encountered an invalid DNSSEC signing key descriptor %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 7664 — The DNS server was unable to sign the zone %1 because it encountered an invalid DNSSEC signing configuration.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7665 — The DNS server was unable to sign the zone %1 because it was unable to access the signing key descriptor %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 7666 — The DNS server encountered an error signing zone %1 during load.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7667 — Keys for the Signing Key Descriptor %1 in zone %2 will be rolled over in less than 1 day.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 7668 — Keys for the Signing Key Descriptor %1 in zone %2 will be rolled over in %3 days.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
__binLength | — |
binary | — |
Event ID 7669 — Keys for the Signing Key Descriptor %1 in zone %2 are starting the rollover process.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7670 — The rollover process for Signing Key Descriptor %1 in zone %2 is complete.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7671 — There was an error rolling keys for Signing Key Descriptor %1 in zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7672 — There was an error rolling keys for Signing Key Descriptor %1 in zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7673 — Retired Signing Key Descriptor %1 in zone %2 has been removed.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7674 — Zone %1 has been transferred to one or more secondary DNS servers.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 7675 — The DNS server has started signing the scope %1 of zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7676 — The scope %1 of zone %2 is signed with DNSSEC.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7677 — The DNS server encountered an error while signing the scope %1 of zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
VirtualizationID | — |
__binLength | — |
binary | — |
Event ID 7678 — The scope %1 of zone %2 is no longer signed with DNSSEC.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7679 — The DNS server encountered an error while unsigning the scope %1 of zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
VirtualizationID | — |
__binLength | — |
binary | — |
Event ID 7680 — Failed to load scopes of zone %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
VirtualizationID | — |
__binLength | — |
binary | — |
Event ID 7681 — Failed to load scope %1 of zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
virtualizationId | — |
__binLength | — |
binary | — |
Event ID 7682 — Failed to load scope %1 of zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
virtualizationId | — |
__binLength | — |
binary | — |
Event ID 7683 — Failed to write data of scope %1 of zone %2 into file %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
VirtualizationID | — |
__binLength | — |
binary | — |
Event ID 7684 — The cache scope %1 was flushed.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 7685 — A scope %1 has been added to server %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7686 — A scope %1 has been deleted from server %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7687 — Failed to load scope %1 of server %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7688 — The size of the cache on DNS server is approaching its configured limit of %1 KB.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 7689 — The size of the cache on DNS server is approaching its configured limit of %1 KB.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 7690 — The size of the cache on DNS server has been brought within its configured limit of %1 KB.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 7691 — DNS service started with less privileges as KDC is unavailable at the moment.
Message
Event ID 7692 — The EDNS option code %1 for scope transaction during zone transfer is invalid.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
__binLength | — |
binary | — |
Event ID 7693 —
Message
Fields
| Name | Description |
|---|---|
Name | — |
Data | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Server-Service
guid: 71A551F5-C893-4849-886B-B5EC8502641E
event_source_name: ''
event_id: 7693
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854779904
time_created: '2022-04-07T16:53:24.111885+00:00'
event_record_id: 23
correlation: {}
execution:
process_id: 2320
thread_id: 2848
channel: DNS Server
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: DNS_EVENT_SCOPE_EDNS_OPCODE_SET
Data:
Name: param1
Value: 65433
Binary: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 7694 — The DNS server encountered an error %1 while signing the zone %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
Event ID 1073741826 — The DNS server has started.
Message
Event ID 1073741827 — The DNS server has shut down.
Message
Event ID 1073741828 — The DNS server has finished the background loading of zones.
Message
Event ID 1073742532 — The DNS server did not detect any zones of either primary or secondary type during initialization.
Message
Event ID 1073742533 — The DNS server has moved the AD-integrated root hint data for all DNS servers in this domain to the {param1} directory partition.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073742534 — An administrator has changed the type and zone storage options of zone {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073742535 — An administrator has changed the type and/or Active Directory location of zone {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073742536 — An administrator has changed the zone storage options for zone {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 1073742537 — An administrator has moved the zone {param1} to a new location in Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 1073742624 — The zone {param1} is configured to accept updates but the A record for the primary server in the zone's SOA record is not available on this DNS ser...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073743826 — The DNS server has written a new version of the boot file.
Message
Event ID 1073743829 — The DNS server has been reconfigured to boot from a boot file.
Message
Event ID 1073744325 — The DNS server has completed a scavenging cycle: Visited Zones = {param1}; Visited Nodes = {param2}; Scavenged Nodes = {param3}; Scavenged Records ...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
Event ID 1073744326 — The DNS server has completed a scavenging cycle but no nodes were visited.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 1073744455 — The DNS server successfully autoconfigured: {param1} {param2} {param3} {param4}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 1073744974 — The DNS server wrote version {param1} of zone {param2} to file {param3}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073745829 — The DNS server received indication that zone {param1} was deleted from the Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073745844 — The DNS server is now starting to load zone {param1} in the background.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073745845 — The DNS server has completed background loading of zone {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 1073746324 — The DNS Application Directory Partition {param1} was created.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 1073746325 — The DNS Application Directory Partition {param1} was deleted.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 1073746326 — The DNS added the local Active Directory to the replication scope of Application Directory Partition {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 1073746327 — The DNS removed the local Active Directory from the replication scope of Application Directory Partition {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 1073746337 — The DNS server detected that it is not enlisted in the replication scope of the directory partition {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073746338 — The DNS server detected that it is not enlisted in the replication scope of the directory partition {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073746347 — The DNS server has detected that the application directory partition {param1} is replicating onto this domain controller.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073746348 — The DNS server has detected that the application directory partition {param1} has finished replicating onto this domain controller.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073747324 — The DNS server received a bad DNS query from {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073747325 — The DNS server encountered a bad packet from {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073747326 — The DNS server received a bad TCP-based DNS message from {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073747328 — The DNS server encountered an invalid domain name in a packet from {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073747329 — The DNS server encountered a domain name exceeding the maximum length in the packet from {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073747330 — The DNS server encountered an invalid domain name offset in a packet from {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073747331 — The DNS server encountered a name offset exceeding the packet length from {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073747332 — The DNS server encountered a packet name exceeding the maximum label count from {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073747333 — The DNS server encountered an invalid DNS update message from {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073747334 — The DNS server encountered an invalid response message from {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073747335 — The DNS server encountered a name with a label whose length exceeds the maximum of 63 bytes from {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073747824 — The DNS server started transfer of version {param1} of zone {param2} to the DNS server at {param3}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073747825 — The DNS server successfully completed transfer of version {param1} of zone {param2} to the DNS server at {param3}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073747826 — The transfer of version {param1} of zone {param2} by the DNS server was aborted by the server at {param3}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073748344 — Zone {param1} was updated to version {param2} of the zone as provided from the master server at {param3}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073748345 — Zone {param1} is synchronized with version {param2} of the zone as provided from the master server at {param3}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073748346 — A more recent version; version {param1} of zone {param2} was found at the DNS server at {param3}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147484057 — The DNS server list of restricted interfaces contains IP addresses that are not configured for use at the server computer.
Message
Event ID 2147484059 — The DNS server has bound one or more socket pool sockets to port numbers from port exclusion range {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147484062 — The DNS server computer currently does not have a DNS domain name.
Message
Event ID 2147484354 — The DNS server does not have a cache or other database entry for root name servers.
Message
Event ID 2147484850 — The DNS server encountered an unsupported 'directory' directive in the server boot file {param1} at line {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147485168 — The DNS server encountered the unknown directive '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147485169 — The DNS server encountered the unsupported directive '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147485170 — The DNS server encountered the obsolete directive '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147485171 — The DNS server encountered the directive '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147485173 — DNSSEC signatures with key tag {param1}; associated with records in zone {param2}; will expire on {param3} (UTC time).
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147485249 — DNS server encountered the obsolete record type {param1} in database file {param2}; line {param3}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147486278 — The DNS server could not configure the network connections of this computer with the local computer's IP address as the preferred DNS server; becau...
Message
Event ID 2147487661 — The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed.
Message
Event ID 2147487665 — The DNS server was unable to load or create the DnsAdmins group.
Message
Event ID 2147487666 — The DNS server was unable to begin background loading of Active Directory-integrated zones.
Message
Event ID 2147487667 — The DNS server attempted to load the Active Directory-integrated zone {param1} in the background but there was an error during load.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147488048 — The DNS server is experiencing high SOA query load.
Message
Event ID 2147488158 — The DNS server was unable to connect to the domain naming FSMO {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147488160 — The DNS server was unable to create the built-in directory partition {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147488163 — The zone {param1} was previously loaded from the directory partition {param2} but another copy of the zone has been found in directory partition {p...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147488168 — The DNS server encountered error {param1} building the zone list from Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147488169 — The DNS server encountered error {param1} attempting to load zone {param2} from Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147488170 — The DNS server has deleted all records for a corrupt DNS node from Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147488699 — The DNS server is using a large amount of memory.
Message
Event ID 2147489651 — The DNS server received a request from {param1} for a UDP-based transfer of the entire zone.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147489652 — The DNS server received a zone transfer request from {param1} for a non-existent or non-authoritative zone {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147490171 — Zone {param1} failed zone refresh check.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147490174 — Zone {param1} version {param2} is newer than version {param3} on DNS server at {param4}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 2147490183 — The master DNS server at {param2} responded to IXFR (Incremental Zone Transfer) request for zone {param1} with an invalid (FORMAT ERROR) response.
Message
Fields
| Name | Description |
|---|---|
param2 | — |
param1 | — |
Event ID 2147490708 — The DNS server could not connect to DNS server at {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147490710 — The DNS server encountered a packet addressed to itself on IP address {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147491148 — The DNS server failed to process a packet from {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147491248 — The global query block list is a feature that prevents attacks on your network by blocking DNS queries for specific host names.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147491264 — The TrustAnchors zone could not be loaded:{param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221225482 — The DNS server could not start because it is dependent on the NTDS service which is not started.
Message
Event ID 3221225583 — The DNS server could not create a thread.
Message
Event ID 3221225603 — The DNS server failed to initialize NetBIOS lookups to support WINSR for reverse lookup zones.
Message
Event ID 3221225612 — The DNS server could not initialize the remote procedure call (RPC) service.
Message
Event ID 3221225622 — The DNS server could not load or initialize the plug-in DLL {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221225875 — The DNS server could not create a Transmission Control Protocol (TCP) socket.
Message
Event ID 3221225876 — The DNS server could not bind a Transmission Control Protocol (TCP) socket to address {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221225877 — The DNS server could not listen on Transmission Control Protocol (TCP) socket for address {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221225878 — The DNS server could not create a User Datagram Protocol (UDP) socket.
Message
Event ID 3221225879 — The DNS server could not bind a User Datagram Protocol (UDP) socket to {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221225880 — The DNS server could not open socket for address {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221225882 — The DNS server list of restricted interfaces does not contain a valid IP address for the server computer.
Message
Event ID 3221225972 — The DNS server has detected that the zone {param1} has invalid or corrupted registry data.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221225973 — The DNS server has detected that the zone {param1} has a missing or corrupted zone type in registry data.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221225974 — The DNS server has detected that for the primary zone {param1} its has no zone file name stored in registry data.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221225975 — The DNS server has detected that the secondary zone {param1} has no master IP addresses in registry data.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221225976 — The DNS server could not create zone {param1} from registry data.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221225977 — The DNS server zone {param1} has invalid or corrupted registry data for {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221225978 — The DNS server has invalid or corrupted registry parameter {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221225979 — The DNS server encountered invalid or corrupted forwarder parameters in registry data.
Message
Event ID 3221226179 — The DNS server is not root authoritative and no root hints were specified in the cache.
Message
Event ID 3221226472 — The DNS server could not open the file {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221226473 — The DNS server could not map file {param1} to memory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221226475 — The DNS server could not find or open the root hints file; Cache.
Message
Event ID 3221226476 — The DNS server could not find or open zone file {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221226480 — The DNS server was unable to create the path for file {param1} in directory {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221226672 — The DNS server could not find or open boot file {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221226673 — The DNS server could not create zone {param1} specified in file {param2} at line {param3}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221226675 — The DNS server encountered a 'forwarders' directive in with no forwarding addresses in file {param1} at line {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221226677 — The DNS server encountered an unknown boot option {param1} in file {param2} at line {param3}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221226678 — DNS server encountered missing database directory name; in file {param1}; line {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221226973 — The DNS server could not parse zone file {param1} for zone {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221226974 — The DNS server could not parse the token '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221226975 — The DNS server could not parse the zone file {param1} at line {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221226976 — The DNS server could not parse an unexpected token '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221226977 — The DNS server unexpected end of line; in zone file {param1} at line {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221226978 — The DNS server encountered invalid token '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221226979 — The DNS server encountered invalid class token '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221226980 — The DNS server is ignoring an invalid resource record in zone file {param1} at line {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221226996 — DNSSEC signatures with key tag {param1}; associated with records in zone {param2}; have expired.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221227012 — The DNS server unable to create domain node.
Message
Event ID 3221227013 — The DNS server encountered invalid domain name '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221227014 — The DNS server encountered invalid domain name '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221227015 — The DNS server encountered domain name '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221227016 — The DNS server encountered an invalid '@' token '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221227017 — The DNS server encountered a name outside of the specified zone in zone file {param1} at line {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221227018 — The DNS server encountered an invalid name server (NS) resource record in zone file {param1} at line {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221227019 — The DNS server encountered an invalid host (A) resource record in zone file {param1} at line {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221227072 — The DNS server encountered an unknown or unsupported resource record (RR) type {param1} in zone file {param2} at line {param3}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221227074 — The DNS server encountered an invalid SOA (Start Of Authority) resource record (RR) in file {param1} at line {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221227082 — The DNS server encountered a resource record (RR) in the zone file {param1} at line {param2} for a domain name with an existing CNAME (alias) RR.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221227083 — The DNS server encountered a CNAME (alias) resource record (RR) in zone file {param1} at line {param2} for a domain name with existing RRs.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221227084 — The DNS server encountered an alias (CNAME or DNAME) resource record (RR) in zone file {param1} at line {param2} that forms an alias loop with anot...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221227085 — The DNS server encountered an invalid preference value '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221227086 — The DNS server encountered a token '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221227088 — The DNS server encountered a text string '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221227089 — The DNS server encountered an invalid IP address '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221227090 — The DNS server encountered an invalid IPv6 address '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221227091 — The DNS server could not find protocol '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221227092 — The DNS server could not find the service '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221227093 — The DNS server encountered the port '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221227122 — The DNS server encountered invalid WINS record in file {param1}; line {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221227123 — The DNS server encountered an invalid WINS reverse lookup (WINSR) resource record (RR) in file {param1} at line {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221227126 — The DNS server encountered an unknown WINS-to-DNS mapping flag {param1} in file {param2} at line {param3}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221227128 — The DNS server encountered a WINS reverse lookup (WINSR) resource record (RR) without a domain specified for resulting names in zone file {param1} ...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221227475 — The DNS server encountered an error writing current configuration back to boot file.
Message
Event ID 3221227672 — The DNS server could not open a registry key.
Message
Event ID 3221227674 — The DNS server could not write a registry key.
Message
Event ID 3221227675 — The DNS server could not delete a registry key.
Message
Event ID 3221227676 — The registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters\.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221228623 — The DNS server unable to write zone file {param1} for zone {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221228624 — The DNS server was unable to open file {param1} for write.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221228625 — The DNS server encountered an error writing to file.
Message
Event ID 3221228632 — The DNS server encountered an non-writeable or unknown resource record (RR) type when writing the zone database to file.
Message
Event ID 3221228634 — The DNS server encountered an unknown protocol writing a well known service (WKS) resource record to the zone file.
Message
Event ID 3221228635 — While writing a well known service (WKS) record to the zone file; the DNS server encountered a port number that is not associated with a known serv...
Message
Event ID 3221229472 — The DNS server was unable to open Active Directory.
Message
Event ID 3221229473 — The DNS server was unable to open zone {param1} in the Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221229474 — The DNS server was unable to add zone {param1} to the Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221229475 — The DNS server was unable to delete zone {param1} in the Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221229476 — The DNS server was unable to complete directory service enumeration of zone {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221229478 — The DNS server could not load the records for the DNS name {param1} found in the Active Directory integrated zone {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221229479 — The DNS server was unable to open zone {param1} in the Active Directory from the application directory partition {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221229482 — The DNS server was unable to create a resource record for {param1} in zone {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221229483 — The DNS server was unable to add or write an update of domain name {param1} in zone {param2} to the Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221229484 — The DNS server timed out attempting to write resource records to the Active Directory at {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221229486 — The DNS server was unable to initialize Active Directory security interfaces.
Message
Event ID 3221229487 — The DNS server has encountered a critical error from the Active Directory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221229488 — The DNS server timed out attempting an Active Directory service operation on {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221229983 — The zone {param1} was not successfully saved to the new directory partition as {param2} due to an error deleting the zone from the old directory pa...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221230577 — The DNS server attempted to cache an CNAME (alias) resource record for the domain node.
Message
Event ID 3221230578 — The DNS server attempted to cache an CNAME (alias) resource record (RR) for a domain name with existing RRs.
Message
Event ID 3221230579 — The DNS server created CNAME (alias) loop caching CNAME resource records (RRs).
Message
Event ID 3221230580 — The DNS server created an CNAME (alias) loop loading CNAME at {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221231996 — Invalid response from master DNS server at {param2} during attempted zone transfer of zone {param1}.
Message
Fields
| Name | Description |
|---|---|
param2 | — |
param1 | — |
Event ID 3221231997 — A zone transfer request for the secondary zone {param1} was refused by the master DNS server at {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221231999 — Zone {param1} expired before it could obtain a successful zone transfer or update from a master server acting as its source for the zone.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221232002 — During transfer of zone {param1} from master at {param2}; the DNS server received a resource record (RR) for domain node {param3} at which an CNAME...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221232003 — During transfer of zone {param1} from master at {param2}; the DNS server received a CNAME (alias) resource record (RR) for domain node {param3} for...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221232004 — During transfer of zone {param1} from master at {param2}; the DNS server received a CNAME (alias) resource record (RR) for domain node {param3} whi...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221232005 — The DNS server could not create a zone transfer thread.
Message
Event ID 3221232006 — Failed transfer of zone {param1} from DNS server at {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221232008 — Invalid IXFR (Incremental Zone Transfer) response from master DNS server at {param2} during attempted incremental transfer of zone {param1}.
Message
Fields
| Name | Description |
|---|---|
param2 | — |
param1 | — |
Event ID 3221232174 — DNS server has updated its own host (A) records.
Message
Event ID 3221232522 — The DNS server recv() function failed.
Message
Event ID 3221232523 — The DNS server recvfrom() function failed.
Message
Event ID 3221232524 — The DNS server send() function failed.
Message
Event ID 3221232525 — The DNS server sendto() function failed.
Message
Event ID 3221232526 — The DNS server select() function failed.
Message
Event ID 3221232527 — The DNS server accept() function failed.
Message
Event ID 3221232528 — The DNS server GetQueuedCompletionStatus() function failed.
Message
Event ID 3221232974 — The DNS server was unable to service a client request due a shortage of available memory.
Message
Event ID 3221232975 — The DNS server could not allocate memory for resource record {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221232976 — The DNS server could not allocate memory for the node of domain name {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |