To manage the performance impact of capturing these network events on your Endpoint Security (HX) Server, toggle the Capture DNS Events option.
You can enable DNS network event capturing through real-time indicator detection processing using the Web UI or the API. This section covers how to enable DNS network event capturing for real-time indicator detection indicator using the Web UI. See the Endpoint Security (HX) REST API Guide for more information on configuring your real-time indicator settings.
Important
On hosts with a high number of events, some events may not be recorded.
Enabling DNS Network Event Capture
To enable DNS network event capture for all of your host endpoints:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
From the Policies table, select the Agent Default Policy and click the policy link to access the Edit Policy page.
Select the Real-Time Indicator Detection tab.
.png)
Verify that the Real-Time Indicator Detection ON/OFF switch is set to ON to enable real-time indicator detection.
.png)
In the Events section, toggle the Capture DNS Events ON/OFF switch to ON
.png)
Click Save.
To enable DNS network event capture for selected host sets:
Note
See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
From the Policies table, click the link for the custom policy you want to modify.
Select the Real-Time Indicator Detection tab.
.png)
Verify that the Real-Time Indicator Detection ON/OFF switch is set to ON to enable real-time indicator detection.
.png)
In the Events section, toggle the Capture DNS Events ON/OFF switch to ON
.png)
Click Save.
Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.
Disabling DNS Network Event Capture
To disable DNS network event capture for all of your host endpoints:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
From the Policies table, select the Agent Default Policy and click the policy link to access the Edit Policy page.
Select the Real-Time Indicator Detection tab.
.png)
In the Events section, toggle the Capture DNS Events ON/OFF switch to OFF.
.png)
Click Save.
To disable DNS network event capture for selected host sets:
Note
If you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
From the Policies table, click the link for the custom policy you want to modify.
Select the Real-Time Indicator Detection tab.
.png)
In the Events section, toggle the Capture DNS Events ON/OFF switch to OFF.
.png)
Click Save.