To mitigate DNS data exfiltration, Infoblox DNS threat analytics employs analytics algorithms that analyze incoming DNS queries and responses to detect DNS tunneling traffic.
The Grid member threat analytics object contains facilities for starting and stopping the DNS threat analytics routines as well as for monitoring the current status of the threat analytics service.
References to member:threatanalytics are object references.
The name part of the Grid member threat analytics object reference has the following components:
- The Grid member host name
The object does not support the following operations:
The object cannot be managed on Cloud Platform members.
These fields are actual members of the object; thus, they can be requested by using _return_fields, if the fields are readable.
The basic version of the object contains the field(s): host_name, ipv4_address, ipv6_address, status.
The Grid member descriptive comment.
Type
String.
Search
The field is available for search via
Notes
The comment cannot be updated.
comment cannot be written.
Determines whether the threat analytics service is enabled.
Type
Bool.
Create
The default value is False.
Search
The field is not available for search.
The Grid member host name.
Type
String.
Search
The field is available for search via
Notes
The host_name is part of the base object.
The host_name cannot be updated.
host_name cannot be written.
The IPv4 Address address of the Grid member.
Type
String.
Search
The field is available for search via
Notes
The ipv4_address is part of the base object.
The ipv4_address cannot be updated.
ipv4_address cannot be written.
The IPv6 Address address of the Grid member.
Type
String.
Search
The field is available for search via
Notes
The ipv6_address is part of the base object.
The ipv6_address cannot be updated.
ipv6_address cannot be written.
Field | Type | Req | R/O | Base | Search |
---|---|---|---|---|---|
comment | String | N | Y | N | : = ~ |
enable_service | Bool | N | N | N | N/A |
host_name | String | N | Y | Y | : = ~ |
ipv4_address | String | N | Y | Y | = ~ |
ipv6_address | String | N | Y | Y | = ~ |
status | String | N | Y | Y | N/A |