Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
A more recent version, version <version number> of zone <DNS zone name> was found at DNS server at <ip address>. Zone transfer is in progress.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the role of a DNS server?
This is a self-explanatory event. If your DNS server is of "Standard Secondary" type, it requests the new version of the authoritative zone from the Master DNS server. This can be inititated in two ways:
1. Your DNS server is checking periodically the version of the SOA record on the primary and if it is found larger than the last time, the server requests a zone transfer.
2. Instantly after a zone change, if you use DNS notify on the primary server.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated