Log Analytics tables for microsoft.securityinsights/dnsnormalized

Table Categories Solutions Supports basic log plan Queries
ASimDnsActivityLogs

The ASim DNS activity schema represents DNS protocol activity, which may be logged either by a DNS server or by a device sending DNS requests to a DNS server. The DNS protocol activity includes DNS queries, DNS server updates, and DNS bulk data transfers. Since the schema represents protocol activity, it is governed by RFCs and officially assigned parameter lists. The DNS activity schema does not represent DNS server audit events.

security SecurityInsights Yes Yes