Where does fqdn get populated during Discovery. We are currently probe based for windows, linux, ip_switch and ip_router and we have a mix of fqdn being populated or not.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎03-18-2020 08:40 AM
We hae customers asking how fqdn gets populated by Discovery and I am having a little trouble figuring that out. It becomes clearer when we move to patterns but that doesn't seem to be happening in the near future so I am wondering how/where that gets set of windows and linux servers; and switches and routers.
- Labels:
-
Discovery
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎03-18-2020 09:40 AM
That happens in the classify sensor with support from a script include, I believe, hostnameJS

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎03-18-2020 09:47 AM
FQDN is set in the Fully qualified domain name field.
We are using patterns now. But if I recall then I think it was DNS sensor scripts that was getting the FQDN from the Shazzam probe result (i.e. input) using the IP address. In Shazzam probe result you will see FQDN of each IP address scanned (if port 53 is open).
-Tanaji
Please mark reponse correct/helpful if applicable
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎07-20-2022 08:13 AM
Hi Tanaji, how do I see the Shazzam probe result? I like,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎07-22-2022 11:55 AM
IN your discovery status record there should be a tab labeled ECCQueue. IN that tab you will find the shazzam probe, look at the input record and you will find the xml that shows the results of the DNS Resolution.