A global energy company gained real-time DNS visibility without flooding its SIEM

With NXLog Platform, the company captured high-value Windows DNS Analytical events at the source, dropped low-value queries before ingestion, and delivered normalized, encrypted telemetry into Palo Alto Networks Cortex XSIAM.

Nxlog energy case study hero 722x429
Group 25926

Business Demand

Strengthen security posture, meet regulatory compliance obligations, and reduce SIEM costs.

Group 25926

Key Challenges

Capture and analyze Windows DNS Analytical logs across heterogeneous infrastructure — Windows, Linux, and network devices — and feed one integration into Palo Alto Networks Cortex XSIAM.

Group 25926

Results

A unified, real-time view of DNS activity, lower SIEM ingestion, auditable encrypted logs, and threat detection on DNS data that was previously unusable.

Local police

The Challenge

A major North American energy company set out to strengthen its security posture and regulatory compliance while reducing SIEM costs. Responsible for critical pipeline systems and power facilities, it needed to capture and analyze Windows DNS telemetry across a wide network of servers as efficiently as possible.

The company's Windows DNS estate was a key telemetry source for identifying suspicious or anomalous network behavior. But DNS Analytical logs are complex and they arrive in bulk: Windows generates them through Event Tracing for Windows (ETW), and analytical events account for the majority of DNS events a server produces. Sending them unfiltered to a SIEM or XDR platform would have overwhelmed resources and driven up costs.

Volume was only part of the problem. The logs also needed parsing and enrichment before they were useful for detection and investigation. The company needed a way to separate the valuable signals from background noise, standardize the data format, and deliver it securely from hundreds of distributed systems — without hurting performance or compliance posture.

Emoji objects

The Solution

The company chose NXLog Platform and deployed NXLog Agent across its DNS infrastructure.

NXLog Agent's native ETW support captures DNS events directly from the Microsoft-Windows-DNSServer provider at the source, without writing them to disk first. Custom filtering rules excluded low-value queries and noise, refocusing collection on high-relevance events: unusual query types, NXDOMAIN responses, and patterns associated with known attack techniques.

Each event was parsed in depth to extract fields such as query names, query types, source IPs, and response codes. NXLog Agent normalized the data into structured JSON and enriched it with metadata, including the server hostname and event timestamp.

TLS encryption and certificate-based authentication secured delivery into Palo Alto Networks Cortex XSIAM, while disk and memory buffering with flow control kept data moving during network interruptions. Event data was collected in a consistent, verifiable form that supports audit and forensic review across the organization.

Why it Worked

Group 26093

Native ETW collection straight from the Windows DNS Server provider

Group 25927

Filtering at the source, before data reaches the SIEM

Group 25928

Structured JSON, enriched with hostname and timestamp

Group 25929

TLS encryption, certificate-based authentication, and buffered delivery

Results

With NXLog Platform, the organization gained a real-time view of security-critical DNS communications across its estate — without flooding its SIEM.

Filtering at the edge reduced ingestion costs while preserving the signal needed for threat detection. Analysts can now investigate DNS-based threats that were previously hidden in noise, using data the team could not practically collect before.

Compliance posture improved through consistent, encrypted, and traceable log collection across hundreds of distributed systems.

Check circle FILL1 wght400 GRAD0 opsz24 12

Unified DNS visibility

One real-time view of DNS activity across the Windows DNS estate

Check circle FILL1 wght400 GRAD0 opsz24 12

Lower SIEM ingestion

Low-value queries dropped at the source, before they reach the platform

Check circle FILL1 wght400 GRAD0 opsz24 12

Stronger threat detection

DNS-based threats surfaced from data that was previously unusable

Check circle FILL1 wght400 GRAD0 opsz24 12

Auditable, encrypted logs

Consistent, encrypted, traceable collection supporting compliance

About the customer

The customer is a major North American energy company that develops and operates critical energy infrastructure across Canada, the United States, and Mexico. Its business spans natural gas pipelines, liquid pipelines, and power generation.

Nxlog energy case study about 560x420