Configuration on the Windows side
To configure the reception of DNS server events using the ETW connector on the Windows side:
- Start the Event viewer by running the following command:
eventvwr.msc
- This opens a window; in that window, go to the Applications and Services Logs → Microsoft → Windows → DNS-Server folder.
- Open the context menu of the DNS-Server folder and select View → Show Analytic and Debug Logs.
data:image/s3,"s3://crabby-images/ebd4a/ebd4a426d29ca4d38d915a0338212c05e4c41dc1" alt="Win_for_etw_1_en.png"
The Audit debug log and Analytical log are displayed.
- Configure the analytic log:
- Open the context menu of the Analytical log and select Properties.
data:image/s3,"s3://crabby-images/26d9a/26d9a6df9aa385dd244ecbbb13369a6b29c17703" alt="Win_for_etw_2_en.png"
- This opens a window; in that window, make sure that in the Max Log Size (KB) field, the value is
1048576
.data:image/s3,"s3://crabby-images/0a20f/0a20f37381484776b97cf14ce778ea14e9a97d71" alt="Win_for_etw_3_en.png"
- Select the Enable logging check box and in the confirmation window, click OK.
data:image/s3,"s3://crabby-images/99c98/99c98dabb433dfc0d356d3c66dbb9397a5351557" alt="Win_for_etw_4_en.png"
The analytic log must be configured as follows:
data:image/s3,"s3://crabby-images/4ee4f/4ee4f0b8fd3704ad73baac5a28ff4ead35c6aa1e" alt="Win_for_etw_5_en.png"
- Click Apply, then click OK.
An error window is displayed.
data:image/s3,"s3://crabby-images/eed29/eed29e8e49f4f5421ba0ac0d675a4f304f1ea626" alt="Win_for_etw_6_en.png"
When analytic log rotation is enabled, events are not displayed. To view events, in the Actions pane, click Stop logging.
data:image/s3,"s3://crabby-images/b11c2/b11c26a7e0871baf34ac284020803cd693975ebb" alt="Win_for_etw_7_en.png"
- Start Computer management as administrator.
- This opens a window; in that window, go to the System Tools → Performance → Startup Event Trace Sessions folder.
data:image/s3,"s3://crabby-images/aab04/aab04349a414f42b9120bf8ef2e2968d55146d3b" alt="Win_for_etw_8_en.png"
- Create a provider:
- Open the context menu of the Startup Event Trace Sessions folder and select Create → Data Collector Set.
data:image/s3,"s3://crabby-images/32e51/32e5176b281f08fa2dd5a6ba1c8c947d900fd790" alt="Win_for_etw_9_en.png"
- This opens a window; in that window, enter the name of the provider and click Next.
data:image/s3,"s3://crabby-images/3ee25/3ee25fb510973a8fa6dffc1025f7b0ef93d7250c" alt="Win_for_etw_10_en.png"
- Click Add... and in the displayed window, select the Microsoft-Windows-DNSServer provider.
data:image/s3,"s3://crabby-images/3dcda/3dcda2b62a868139b71b1feb6bfc2681c2eee658" alt="Win_for_etw_11_en.png"
The KUMA agent with the ETW connector works only with System.Provider.Guid: {EB79061A-A566-4698-9119-3ED2807060E7} - Microsoft-Windows-DNSServer.
- Click Next twice, then click Finish.
- Open the context menu of the created provider and select Start As Event Trace Session.
data:image/s3,"s3://crabby-images/2f21f/2f21f48881742ca76194cce47584ca94c1b781d6" alt="Win_for_etw_13_en.png"
- Go to the Event Trace Sessions folder.
Event trace sessions are displayed.
- Open the context menu of the created event trace session and select Properties.
- This opens a window; in that window, select the Trace Sessions tab and in the Stream Mode drop-down list, select Real Time.
data:image/s3,"s3://crabby-images/feefe/feefefce039a9078fa78745cb55646f144e057be" alt="Win_for_etw_14_en.png"
- Click Apply, then click OK.
DNS server event reception using the ETW connector is configured.
Page top