Control D DNS
Overview
Control D is a cloud DNS service that filters, blocks, and redirects DNS traffic for devices, networks, and organizations. Control D can stream the DNS queries it handles for an Organization to Sekoia.io as DNS query events. In this documentation you will learn how to receive Control D DNS query logs in Sekoia.io.
- Vendor: Control D
- Supported environment: Cloud service (SaaS)
- Detection based on: Telemetry
- Supported application or feature: DNS records
Each event is one DNS query handled by Control D. The Control D DNS format normalizes the query name and type, the response code and answered IP addresses, the client source IP, the DNS protocol, the Control D Organization, and the Control D action (pass, block, redirect_ip, redirect_loc, fail) together with the trigger that caused it.
High-Level Architecture Diagram
- Type of integration: Outbound (PUSH to Sekoia.io)
- Schema: Control D managed streaming → HTTPS → Sekoia.io Control D DNS intake
Control D operates the streaming service and pushes events directly to the Sekoia.io HTTPS intake endpoint. No customer-hosted receiver, forwarder, or Sekoia.io connector is required.
Specification
Prerequisites
- Resource:
- A Control D Organization account eligible for SIEM log streaming
- Full Analytics enabled on every Control D Endpoint whose DNS queries should be streamed. Control D then processes and stores detailed query data for those Endpoints, so enable it only where streaming is intended.
- The IDs of the Control D Organization and of any Sub-Organizations to include, and the Organization's Analytics Storage Region
- Network:
- None on the customer side. Control D initiates the outbound HTTPS connection to Sekoia.io.
- Permissions:
- Permission to create an intake in a Sekoia.io FRA1 workspace
Note
The Control D Analytics Storage Region is where Control D stores your DNS analytics. It is independent from the Sekoia.io region of your workspace. The Control D streaming service currently delivers to the FRA1 Sekoia.io region only.
Transport Protocol/Method
- Direct HTTP(S) — Control D pushes events to Sekoia.io
Logs details
- Supported functionalities: See section Overview
- Supported type(s) of structure: JSON Lines (one JSON event per line)
Control D sends POST requests to https://intake.sekoia.io/plain/batch, authenticated with the X-SEKOIAIO-INTAKE-KEY header and delivered over TLS with certificate verification. Each request body is JSON Lines: one JSON object per line, not a JSON array.
Warning
Only the FRA1 endpoint is currently supported by the Control D streaming service. Workspaces in other Sekoia.io regions cannot receive Control D DNS events yet.
Step-by-Step Configuration Procedure
Instruction on Sekoia
Configure Your Intake
This section will guide you through creating the intake object in Sekoia, which provides a unique identifier called the "Intake key." The Intake key is essential for later configuration, as it references the Community, Entity, and Parser (Intake Format) used when receiving raw events on Sekoia.
- Go to the Sekoia Intake page.
- Click on the
+ New Intakebutton at the top right of the page. - Search for your Intake by the product name in the search bar.
- Give it a Name and associate it with an Entity (and a Community if using multi-tenant mode).
- Click on
Create.
Note
For more details on how to use the Intake page and to find the Intake key you just created, refer to this documentation.
Select Control D DNS as the intake format. Keep the intake key at hand: it is required for the activation request below.
Instructions on the 3rd party solution
Control D activates the stream for you. There is no self-service setting to enable in the Control D dashboard.
- Contact Control D Support while signed in to the Organization account and request Sekoia.io SIEM log streaming.
- Provide the Control D Organization ID, the IDs of any Sub-Organizations to include, the Organization's Analytics Storage Region, and confirmation that the Sekoia.io workspace is in FRA1.
- Share the intake key only through the secure exchange method agreed with Control D Support. Do not send it in a public issue, chat room, or email thread.
- Wait for Control D Support to confirm that the stream is active.
Note
Treat the intake key as a secret. Anyone who holds it can submit events to your intake.
Enjoy your events on the Events page
After Control D confirms activation:
- Generate a fresh DNS query from a Control D Endpoint that has Full Analytics enabled.
- Confirm that the query appears in the Control D Activity Log.
- On the Sekoia.io Events page, filter on the Control D DNS intake you created and confirm that the event is present.
- Check the event timestamp,
dns.question.name,observer.vendor: Control D, and the expected Control D action inevent.actionandcontrold.action.
Raw messages arriving on the intake are not sufficient proof: the fields above must be populated, which shows that the event was parsed by the Control D DNS format.
Raw Events Samples
In this section, you will find examples of raw logs as generated natively by the source. These examples are provided to help integrators understand the data format before ingestion into Sekoia.io. It is crucial for setting up the correct parsing stages and ensuring that all relevant information is captured.
{
"time": "2026-04-02T14:20:53.735Z",
"query": "testquery.com",
"query_type": "A",
"src_ip": "192.0.2.100",
"reply_code_id": 0,
"protocol": "doh",
"answers": [
{
"ips": [
"198.51.100.1",
"198.51.100.2",
"198.51.100.3",
"198.51.100.4",
"198.51.100.5",
"198.51.100.6"
],
"geoip": {
"countryCode": "US",
"isp": "Test ISP",
"asn": 10000
}
}
],
"organisation": {
"id": "testOrgID",
"name": ""
},
"organization": {
"id": "testOrgID",
"name": ""
},
"device": {
"id": "testDeviceID",
"name": ""
},
"controld_action": 1,
"controld_trigger": "default",
"source_ip": {
"countryCode": "CA",
"city": "Toronto",
"isp": "Test Internet Provider",
"asn": 42069
}
}
Detection section
The following section provides information for those who wish to learn more about the detection capabilities enabled by collecting this intake. It includes details about the built-in rule catalog, event categories, and ECS fields extracted from raw events. This is essential for users aiming to create custom detection rules, perform hunting activities, or pivot in the events page.
Event Categories
The following table lists the data source offered by this integration.
| Data Source | Description |
|---|---|
DNS records |
DNS queries are fully analyzed |
In details, the following table denotes the type of events produced by this integration.
| Name | Values |
|---|---|
| Kind | `` |
| Category | ["network"] |
| Type | ["info"] |
Transformed Events Samples after Ingestion
This section demonstrates how the raw logs will be transformed by our parsers. It shows the extracted fields that will be available for use in the built-in detection rules and hunting activities in the events page. Understanding these transformations is essential for analysts to create effective detection mechanisms with custom detection rules and to leverage the full potential of the collected data.
{
"message": "{\"time\":\"2026-04-02T14:20:53.735Z\",\"query\":\"testquery.com\",\"query_type\":\"A\",\"src_ip\":\"192.0.2.100\",\"reply_code_id\":0,\"protocol\":\"doh\",\"answers\":[{\"ips\":[\"198.51.100.1\",\"198.51.100.2\",\"198.51.100.3\",\"198.51.100.4\",\"198.51.100.5\",\"198.51.100.6\"],\"geoip\":{\"countryCode\":\"US\",\"isp\":\"Test ISP\",\"asn\":10000}}],\"organisation\":{\"id\":\"testOrgID\",\"name\":\"\"},\"organization\":{\"id\":\"testOrgID\",\"name\":\"\"},\"device\":{\"id\":\"testDeviceID\",\"name\":\"\"},\"controld_action\":1,\"controld_trigger\":\"default\",\"source_ip\":{\"countryCode\":\"CA\",\"city\":\"Toronto\",\"isp\":\"Test Internet Provider\",\"asn\":42069}}",
"event": {
"action": "pass",
"category": [
"network"
],
"type": [
"info"
]
},
"@timestamp": "2026-04-02T14:20:53.735000Z",
"controld": {
"action": "pass",
"trigger": "default"
},
"dns": {
"answers": [
{
"data": "198.51.100.1",
"type": "A"
},
{
"data": "198.51.100.2",
"type": "A"
},
{
"data": "198.51.100.3",
"type": "A"
},
{
"data": "198.51.100.4",
"type": "A"
},
{
"data": "198.51.100.5",
"type": "A"
},
{
"data": "198.51.100.6",
"type": "A"
}
],
"question": {
"name": "testquery.com",
"registered_domain": "testquery.com",
"top_level_domain": "com",
"type": "A"
},
"response_code": "NOERROR"
},
"network": {
"protocol": "doh"
},
"observer": {
"product": "Control D DNS",
"type": "dns",
"vendor": "Control D"
},
"organization": {
"id": "testOrgID"
},
"related": {
"hosts": [
"testquery.com"
],
"ip": [
"192.0.2.100"
]
},
"source": {
"address": "192.0.2.100",
"ip": "192.0.2.100"
}
}
Extracted Fields
The following table lists the fields that are extracted, normalized under the ECS format, analyzed and indexed by the parser. It should be noted that infered fields are not listed.
| Name | Type | Description |
|---|---|---|
@timestamp |
date |
Date/time when the event originated. |
controld.action |
keyword |
The action taken by Control D. |
controld.spoof.target |
keyword |
If the request was redirected, this is where it was redirected to. |
controld.trigger |
keyword |
The reason the action was taken. |
controld.trigger.name |
keyword |
The name of the trigger that caused the action, if any. |
dns.answers |
object |
Array of DNS answers. |
dns.question.name |
keyword |
The name being queried. |
dns.question.type |
keyword |
The type of record being queried. |
event.action |
keyword |
The action captured by the event. |
event.category |
keyword |
Event category. The second categorization field in the hierarchy. |
event.type |
keyword |
Event type. The third categorization field in the hierarchy. |
network.protocol |
keyword |
Application protocol name. |
observer.product |
keyword |
The product name of the observer. |
observer.type |
keyword |
The type of the observer the data is coming from. |
observer.vendor |
keyword |
Vendor name of the observer. |
organization.id |
keyword |
Unique identifier for the organization. |
organization.name |
keyword |
Organization name. |
source.ip |
ip |
IP address of the source. |
For more information on the Intake Format, please find the code of the Parser, Smart Descriptions, and Supported Events here.
Troubleshooting
If no events arrive, or events stop arriving:
- Confirm that Full Analytics is still enabled on the affected Control D Endpoints.
- Confirm that the Organization and Sub-Organization IDs given to Control D Support are correct and still cover the Endpoints in question.
- Confirm that the Sekoia.io workspace is in the FRA1 region.
- Confirm that the intake is enabled in Sekoia.io and that its key has not been changed.
- If the intake key was rotated or replaced, send the new key to Control D Support through the agreed secure method, then confirm that delivery resumes with a fresh DNS query.
- If the stream still produces no events, contact Control D Support.
Further readings
- Control D Support
- Control D SIEM streaming overview
- Control D log field reference
- The code of the Intake format is available here.