Skip to content

ServiceRadar

Open navigation

Security

DNS security and RPZ telemetry

See which clients hit which DNS policies, with domain, source, and policy context in the same place you already investigate the rest of the network.

Turn PowerDNS Response Policy Zone (RPZ) hits into first-class security events—collected at the resolver, then searchable with SRQL next to inventory, flows, and other detections.

DNS policy hits are security events, not log archaeology

RPZ is where many networks enforce blocklists, sinkholes, and category policy. The value is not another syslog stream—it is knowing which client asked for which domain, which policy matched, and hunting that signal next to inventory, flows, and detections.

  • Capture policy hits where DNS is already enforced
  • Keep domain, client, and policy context with the event
  • Search and investigate with SRQL like other security signal
  • No separate DNS-only console for day-to-day triage

Built for PowerDNS today

If you already run PowerDNS for recursive resolution and RPZ policy, ServiceRadar can take those policy hits and put them on the same operational surface as the rest of your monitoring—without asking operators to live in resolver logs.

  • PowerDNS Recursor with RPZ is the path available now
  • Focus on policy verdicts that matter, not every recursive query
  • Collection stays on the resolver edge you already operate
  • Deploy and assign through the same agent and package model as other edge capabilities

Structured events operators can actually use

Policy hits show up as structured DNS activity—not a freeform dump. Operators get domain, client, and policy identity in a form that is searchable and consistent with how other security signal is presented.

  • OCSF-shaped DNS Activity for a shared investigation language
  • Domain, client, and which policy matched—front and center
  • Hunt with SRQL and event search alongside the rest of the estate
  • Display contracts so records render cleanly in product views

Edge collection, not a hole in the resolver

DNS security telemetry should not force every site’s resolver into a broad management plane. Signal is collected next to where policy runs, then joins ServiceRadar over the same authenticated edge path you already trust for monitoring.

  • Keep resolver hosts out of a freeform collector free-for-all
  • Use the edge agent path you already deploy for site operations
  • Scope collection with fleet assignment instead of one-off host hacks
  • Details for install and Recursor config live in the product docs

Fits the wider security picture

DNS policy hits sit beside endpoint software risk, flow intelligence, and other detections. Recent policy activity can also enrich network context when you are already looking at conversations—more signal on the same plane, not a second product.

  • Hunt RPZ hits next to device and network context
  • Complement software risk and threat-feed matching with resolver-side policy evidence
  • Same investigation habits as the rest of ServiceRadar
  • Open-source core you can inspect and self-host

Coming soon: Active Directory DNS

PowerDNS is shipping today. Next up is an Active Directory DNS plugin so Windows and hybrid estates can feed DNS security signal into the same place—without standing up a separate Microsoft-only console.

  • Coming soon: Active Directory DNS coverage for enterprise Windows sites
  • Same goal as PowerDNS: security-relevant DNS activity you can investigate with everything else
  • Aimed at domain controllers and Windows DNS roles common in the field
  • PowerDNS RPZ path remains available now while AD coverage lands

FAQs

What DNS software does this support?

PowerDNS with RPZ is available today. An Active Directory DNS plugin is coming soon for Windows and hybrid environments.

Is Active Directory DNS supported yet?

Not yet. An Active Directory DNS plugin is coming soon so AD and hybrid sites can send DNS security signal into ServiceRadar the same way PowerDNS sites do—without a separate AD-only product.

Do we ship every DNS query?

By default, no. The PowerDNS path focuses on RPZ and related policy hits so you keep volume on security-relevant verdicts instead of full recursive query traffic.

How do operators find DNS policy hits?

They show up as structured DNS activity events. Use event search and SRQL alongside your other security and network investigations.

Does this open the resolver to the control plane?

No. Collection stays local to the resolver edge and joins ServiceRadar over the same authenticated agent path used for other edge monitoring—not a new inbound management hole.

Where are the technical docs?

Install, Recursor configuration, and operator details are in the PowerDNS telemetry add-on docs .

Is there a developer reference for the add-on?

For builders who need the package contract, see the PowerDNS add-on developer reference .