Skip to content

Control D DNS

Overview

Control D is a cloud DNS service that filters, blocks, and redirects DNS traffic for devices, networks, and organizations. Control D can stream the DNS queries it handles for an Organization to Sekoia.io as DNS query events. In this documentation you will learn how to receive Control D DNS query logs in Sekoia.io.

  • Vendor: Control D
  • Supported environment: Cloud service (SaaS)
  • Detection based on: Telemetry
  • Supported application or feature: DNS records

Each event is one DNS query handled by Control D. The Control D DNS format normalizes the query name and type, the response code and answered IP addresses, the client source IP, the DNS protocol, the Control D Organization, and the Control D action (pass, block, redirect_ip, redirect_loc, fail) together with the trigger that caused it.

High-Level Architecture Diagram

  • Type of integration: Outbound (PUSH to Sekoia.io)
  • Schema: Control D managed streaming → HTTPS → Sekoia.io Control D DNS intake

Control D operates the streaming service and pushes events directly to the Sekoia.io HTTPS intake endpoint. No customer-hosted receiver, forwarder, or Sekoia.io connector is required.

Specification

Prerequisites

  • Resource:
    • A Control D Organization account eligible for SIEM log streaming
    • Full Analytics enabled on every Control D Endpoint whose DNS queries should be streamed. Control D then processes and stores detailed query data for those Endpoints, so enable it only where streaming is intended.
    • The IDs of the Control D Organization and of any Sub-Organizations to include, and the Organization's Analytics Storage Region
  • Network:
    • None on the customer side. Control D initiates the outbound HTTPS connection to Sekoia.io.
  • Permissions:
    • Permission to create an intake in a Sekoia.io FRA1 workspace

Note

The Control D Analytics Storage Region is where Control D stores your DNS analytics. It is independent from the Sekoia.io region of your workspace. The Control D streaming service currently delivers to the FRA1 Sekoia.io region only.

Transport Protocol/Method

  • Direct HTTP(S) — Control D pushes events to Sekoia.io

Logs details

  • Supported functionalities: See section Overview
  • Supported type(s) of structure: JSON Lines (one JSON event per line)

Control D sends POST requests to https://intake.sekoia.io/plain/batch, authenticated with the X-SEKOIAIO-INTAKE-KEY header and delivered over TLS with certificate verification. Each request body is JSON Lines: one JSON object per line, not a JSON array.

Warning

Only the FRA1 endpoint is currently supported by the Control D streaming service. Workspaces in other Sekoia.io regions cannot receive Control D DNS events yet.

Step-by-Step Configuration Procedure

Instruction on Sekoia

Configure Your Intake

This section will guide you through creating the intake object in Sekoia, which provides a unique identifier called the "Intake key." The Intake key is essential for later configuration, as it references the Community, Entity, and Parser (Intake Format) used when receiving raw events on Sekoia.

  1. Go to the Sekoia Intake page.
  2. Click on the + New Intake button at the top right of the page.
  3. Search for your Intake by the product name in the search bar.
  4. Give it a Name and associate it with an Entity (and a Community if using multi-tenant mode).
  5. Click on Create.

Note

For more details on how to use the Intake page and to find the Intake key you just created, refer to this documentation.

Select Control D DNS as the intake format. Keep the intake key at hand: it is required for the activation request below.

Instructions on the 3rd party solution

Control D activates the stream for you. There is no self-service setting to enable in the Control D dashboard.

  1. Contact Control D Support while signed in to the Organization account and request Sekoia.io SIEM log streaming.
  2. Provide the Control D Organization ID, the IDs of any Sub-Organizations to include, the Organization's Analytics Storage Region, and confirmation that the Sekoia.io workspace is in FRA1.
  3. Share the intake key only through the secure exchange method agreed with Control D Support. Do not send it in a public issue, chat room, or email thread.
  4. Wait for Control D Support to confirm that the stream is active.

Note

Treat the intake key as a secret. Anyone who holds it can submit events to your intake.

Enjoy your events on the Events page

After Control D confirms activation:

  1. Generate a fresh DNS query from a Control D Endpoint that has Full Analytics enabled.
  2. Confirm that the query appears in the Control D Activity Log.
  3. On the Sekoia.io Events page, filter on the Control D DNS intake you created and confirm that the event is present.
  4. Check the event timestamp, dns.question.name, observer.vendor: Control D, and the expected Control D action in event.action and controld.action.

Raw messages arriving on the intake are not sufficient proof: the fields above must be populated, which shows that the event was parsed by the Control D DNS format.

Raw Events Samples

In this section, you will find examples of raw logs as generated natively by the source. These examples are provided to help integrators understand the data format before ingestion into Sekoia.io. It is crucial for setting up the correct parsing stages and ensuring that all relevant information is captured.

{
    "time": "2026-04-02T14:20:53.735Z",
    "query": "testquery.com",
    "query_type": "A",
    "src_ip": "192.0.2.100",
    "reply_code_id": 0,
    "protocol": "doh",
    "answers": [
        {
            "ips": [
                "198.51.100.1",
                "198.51.100.2",
                "198.51.100.3",
                "198.51.100.4",
                "198.51.100.5",
                "198.51.100.6"
            ],
            "geoip": {
                "countryCode": "US",
                "isp": "Test ISP",
                "asn": 10000
            }
        }
    ],
    "organisation": {
        "id": "testOrgID",
        "name": ""
    },
    "organization": {
        "id": "testOrgID",
        "name": ""
    },
    "device": {
        "id": "testDeviceID",
        "name": ""
    },
    "controld_action": 1,
    "controld_trigger": "default",
    "source_ip": {
        "countryCode": "CA",
        "city": "Toronto",
        "isp": "Test Internet Provider",
        "asn": 42069
    }
}

Detection section

The following section provides information for those who wish to learn more about the detection capabilities enabled by collecting this intake. It includes details about the built-in rule catalog, event categories, and ECS fields extracted from raw events. This is essential for users aiming to create custom detection rules, perform hunting activities, or pivot in the events page.

Event Categories

The following table lists the data source offered by this integration.

Data Source Description
DNS records DNS queries are fully analyzed

In details, the following table denotes the type of events produced by this integration.

Name Values
Kind ``
Category ["network"]
Type ["info"]

Transformed Events Samples after Ingestion

This section demonstrates how the raw logs will be transformed by our parsers. It shows the extracted fields that will be available for use in the built-in detection rules and hunting activities in the events page. Understanding these transformations is essential for analysts to create effective detection mechanisms with custom detection rules and to leverage the full potential of the collected data.

{
    "message": "{\"time\":\"2026-04-02T14:20:53.735Z\",\"query\":\"testquery.com\",\"query_type\":\"A\",\"src_ip\":\"192.0.2.100\",\"reply_code_id\":0,\"protocol\":\"doh\",\"answers\":[{\"ips\":[\"198.51.100.1\",\"198.51.100.2\",\"198.51.100.3\",\"198.51.100.4\",\"198.51.100.5\",\"198.51.100.6\"],\"geoip\":{\"countryCode\":\"US\",\"isp\":\"Test ISP\",\"asn\":10000}}],\"organisation\":{\"id\":\"testOrgID\",\"name\":\"\"},\"organization\":{\"id\":\"testOrgID\",\"name\":\"\"},\"device\":{\"id\":\"testDeviceID\",\"name\":\"\"},\"controld_action\":1,\"controld_trigger\":\"default\",\"source_ip\":{\"countryCode\":\"CA\",\"city\":\"Toronto\",\"isp\":\"Test Internet Provider\",\"asn\":42069}}",
    "event": {
        "action": "pass",
        "category": [
            "network"
        ],
        "type": [
            "info"
        ]
    },
    "@timestamp": "2026-04-02T14:20:53.735000Z",
    "controld": {
        "action": "pass",
        "trigger": "default"
    },
    "dns": {
        "answers": [
            {
                "data": "198.51.100.1",
                "type": "A"
            },
            {
                "data": "198.51.100.2",
                "type": "A"
            },
            {
                "data": "198.51.100.3",
                "type": "A"
            },
            {
                "data": "198.51.100.4",
                "type": "A"
            },
            {
                "data": "198.51.100.5",
                "type": "A"
            },
            {
                "data": "198.51.100.6",
                "type": "A"
            }
        ],
        "question": {
            "name": "testquery.com",
            "registered_domain": "testquery.com",
            "top_level_domain": "com",
            "type": "A"
        },
        "response_code": "NOERROR"
    },
    "network": {
        "protocol": "doh"
    },
    "observer": {
        "product": "Control D DNS",
        "type": "dns",
        "vendor": "Control D"
    },
    "organization": {
        "id": "testOrgID"
    },
    "related": {
        "hosts": [
            "testquery.com"
        ],
        "ip": [
            "192.0.2.100"
        ]
    },
    "source": {
        "address": "192.0.2.100",
        "ip": "192.0.2.100"
    }
}

Extracted Fields

The following table lists the fields that are extracted, normalized under the ECS format, analyzed and indexed by the parser. It should be noted that infered fields are not listed.

Name Type Description
@timestamp date Date/time when the event originated.
controld.action keyword The action taken by Control D.
controld.spoof.target keyword If the request was redirected, this is where it was redirected to.
controld.trigger keyword The reason the action was taken.
controld.trigger.name keyword The name of the trigger that caused the action, if any.
dns.answers object Array of DNS answers.
dns.question.name keyword The name being queried.
dns.question.type keyword The type of record being queried.
event.action keyword The action captured by the event.
event.category keyword Event category. The second categorization field in the hierarchy.
event.type keyword Event type. The third categorization field in the hierarchy.
network.protocol keyword Application protocol name.
observer.product keyword The product name of the observer.
observer.type keyword The type of the observer the data is coming from.
observer.vendor keyword Vendor name of the observer.
organization.id keyword Unique identifier for the organization.
organization.name keyword Organization name.
source.ip ip IP address of the source.

For more information on the Intake Format, please find the code of the Parser, Smart Descriptions, and Supported Events here.

Troubleshooting

If no events arrive, or events stop arriving:

  • Confirm that Full Analytics is still enabled on the affected Control D Endpoints.
  • Confirm that the Organization and Sub-Organization IDs given to Control D Support are correct and still cover the Endpoints in question.
  • Confirm that the Sekoia.io workspace is in the FRA1 region.
  • Confirm that the intake is enabled in Sekoia.io and that its key has not been changed.
  • If the intake key was rotated or replaced, send the new key to Control D Support through the agreed secure method, then confirm that delivery resumes with a fresh DNS query.
  • If the stream still produces no events, contact Control D Support.

Further readings