---
title: "dns.windows"
canonical: "https://docs.devo.com/space/latest/94661904/dns.windows"
format: markdown
---
> Macro (toc)

## Purpose

Use tags in this category to identify events generated by the [Windows Server Domain Name System (DNS)](https://learn.microsoft.com/en-us/windows-server/networking/dns/dns-overview).

## Send it

Data should be sent using the [Devo Relay](https://docs.devo.com/space/latest/96468993/Devo+Relay).

Create a simple rule on your Devo Relay that applies the `dns.windows` tag to all events arriving on a specified port.

### Example [relay rules](https://docs.devo.com/space/latest/96469377/Defining+a+relay+rule)

```
         Source message: 
            Source data: 
             Source tag: 
             Target tag: dns.windows
Sent without syslog tag: true
        Stop processing: true
```

## Secure it

The [network.dns](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95126195/network.dns#Secure-it) and [domains.all](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95126139/domains.all#Secure-it) union tables help monitor events from this table.

**Exhange Alert Pack:**

- [Protocol Tunneling (MITRE Att&ck Technique: T1572)](https://docs.devo.com/space/latest/326500411/Mitre+alert+packs+T1500-1599#T1572)

## Tags and tables

| **[Tags](https://docs.devo.com/space/latest/95126204/About+Devo+tags)** | **[Data tables](https://docs.devo.com/space/latest/94764298/Run+a+search+using+a+finder)** |
| --- | --- |
| `dns.windows` | `dns.windows` |