Hi - I am looking for any advice on creating a dashboard item using flows. We are running the latest QRadar, and also now have QNI in place.
Use case: I want to have a dashboard that will show any outbound (external) DNS queries that may be rogue.
Our DNS setup: Clients query our internal AD domain controllers, and those DC's will forward to DNS server in our DMZ. Only our DMZ servers are allowed to go external to either google or to our MSP DNS servers.
What I did so far: I created a reference set for all of our domain controllers. I created a reference set for DMZ DNS servers. I created a reference set for allowed external DNS servers (our MSP DNS servers and google).
Need help/advice: From Network Activity, if I query on port 53 traffic, can I exclude traffic that is acceptable by design, and only show external traffic with source NOT from our DMZ DNS servers? I would also like to make this a dashboard item. I have done this with Logs, but not with Flows.
------------------------------
Eric Puente
------------------------------