These are the event fields specific to the Sysmon module.
sysmon.dns.status
Windows status code returned for the DNS query.
type: keyword
Most Popular
Video
Get Started with Elasticsearch
Intro to Kibana
ELK for Logs & Metrics