# Convert-DNSDebugLogFile

LLMS index: [llms.txt](/v1.2.1.0/llms.txt)

---

<!-- This file is auto-generated using PlatyPS + HUGO Workflow automation. Avoid editing directly! Original Front-Matter:
date: 2026-05-27
document type: cmdlet
external help file: DNSServer.DebugLogParser-Help.xml
flagTranslation: Primary
HelpUri: https://github.com/AndiBellstedt/DNSServer.DebugLogParser
Locale: en-US
Module Name: DNSServer.DebugLogParser
ms.date: 05/27/2026
PlatyPS schema version: 2024-05-01
title: Convert-DNSDebugLogFile
type: docs
-->



## SYNOPSIS

Transforms Windows DNS Server debug logs into structured CSV format for analysis and reporting.

## SYNTAX

### __AllParameterSets

```
Convert-DNSDebugLogFile [-InputFile] <string[]> [[-OutputFile] <string>] [[-Delimiter] <string>]
 [[-ComputerName] <string>] [[-OutputType] <string>] [[-ContextFilter] <string[]>]
 [[-InputCulture] <cultureinfo>] [[-OutputCulture] <cultureinfo>] [-SkipHeaderValidation]
 [-RemoveSourceFile] [-CompressOutput] [-NoDetailsParsing] [-WhatIf] [-Confirm] [<CommonParameters>]
```

## ALIASES

This cmdlet has the following aliases,

## DESCRIPTION

Converts Windows DNS Server debug log files into structured CSV data that can be analyzed
in Excel, Power BI, SQL databases, or SIEM tools.
Designed for security analysis, performance
monitoring, troubleshooting, and compliance reporting.

The cmdlet parses DNS debug logs and writes a consistent CSV output for analysis.
The CSV output contains 18 columns, including an `Information` column for event/diagnostic text,
an optional `Details` JSON column for Packet detail blocks, and an always-present `ComputerName`
column (empty unless specified).

KEY FEATURES:
- Streaming processing avoids loading the full file into memory (suitable for very large logs)
- High-performance parsing optimized for large files (100MB+)
- Customizable CSV delimiter (default: semicolon)
- Optional statistical summaries with aggregated metrics
- Context filtering (Packet, Event, Note, and additional contexts) to focus on specific log entry types
- Culture-aware date parsing and formatting for international servers
- Pipeline support for batch processing multiple files
- Optional compression of output files (ZIP format)
- Optional automatic removal of source files after processing
- Header validation to ensure data integrity

OUTPUT FORMAT:
The ComputerName column is always included at the end of each record.
If the -ComputerName
parameter is not specified, the column will be empty.
This ensures consistent output structure
for multi-server consolidation scenarios.

PERFORMANCE:
Optimized using StreamReader/StreamWriter with 64KB buffers, streaming processing for
memory-efficient handling of large files, string operations instead of regex, manual CSV
generation, and efficient hashtable-based statistics collection.

COMPATIBILITY:
- PowerShell 5.1+ (Desktop and Core editions)
- Windows Server 2016+
- DNS Server 2012 R2 through 2025 log formats

## EXAMPLES

### EXAMPLE 1

```powershell
PS C:\> Convert-DNSDebugLogFile -InputFile "C:\Logs\dns.log"
```

Converts the DNS debug log using default settings (both data and statistics files with semicolon delimiter).
Output:
- C:\Logs\dns.csv
- C:\Logs\dns_Statistic.csv
- C:\Logs\dns_PacketStatistic.csv

### EXAMPLE 2

```powershell
PS C:\> Convert-DNSDebugLogFile -InputFile "C:\Logs\dns.log" -OutputType CSV
```

Generates only the data file without statistics.
Output: C:\Logs\dns.csv

### EXAMPLE 3

```powershell
PS C:\> Convert-DNSDebugLogFile -InputFile "C:\Logs\dns.log" -OutputType Statistic
```

Generates only the statistics file with aggregated metrics.
Output:
- C:\Logs\dns_Statistic.csv
- C:\Logs\dns_PacketStatistic.csv

### EXAMPLE 4

```powershell
PS C:\> Convert-DNSDebugLogFile -InputFile "C:\Logs\dns.log" -OutputFile "C:\Output\parsed.csv"
```

Converts the log to a custom output location.
Output: C:\Output\parsed.csv

### EXAMPLE 5

```powershell
PS C:\> Convert-DNSDebugLogFile -InputFile "C:\Logs\dns.log" -Delimiter "," -ComputerName "DNS01" -OutputType Both
```

Converts with comma delimiter and adds ComputerName column with value "DNS01".
Output:
- C:\Logs\dns.csv
- C:\Logs\dns_Statistic.csv
- C:\Logs\dns_PacketStatistic.csv

### EXAMPLE 6

```powershell
PS C:\> Get-ChildItem "C:\Logs\*.log" | Convert-DNSDebugLogFile -OutputType Both
```

Batch processes multiple DNS debug log files via pipeline.
Output: For each .log file, generates .csv and _statistic.csv files

### EXAMPLE 7

```powershell
PS C:\> Convert-DNSDebugLogFile -InputFile "C:\Logs\dns.log" -CompressOutput
```

Converts and compresses output to ZIP archive.
Output: C:\Logs\dns.zip (containing dns.csv + statistics files)

### EXAMPLE 8

```powershell
PS C:\> Convert-DNSDebugLogFile -InputFile "C:\Logs\dns.log" -RemoveSourceFile -Verbose
```

Converts the log and removes the source file after successful processing.
Verbose output confirms file removal.

### EXAMPLE 9

```powershell
PS C:\> Convert-DNSDebugLogFile -InputFile "C:\Logs\dns.log" -InputCulture 'de-DE' -OutputCulture 'en-US'
```

Parses German date format (DD.MM.YYYY) and outputs in US format (MM/DD/YYYY).
Use when processing logs from servers with different regional settings.

### EXAMPLE 10

```powershell
PS C:\> Convert-DNSDebugLogFile -InputFile "C:\Logs\dns.log" -ContextFilter 'Packet'
```

Converts only DNS query/response packet entries, excluding EVENT and Note entries.
Use to focus analysis on actual DNS traffic.

### EXAMPLE 11

```powershell
PS C:\> Convert-DNSDebugLogFile -InputFile "C:\Logs\dns.log" -ContextFilter 'Packet','Event'
```

Converts both DNS query/response packets and server events, excluding Note and other entries.
Use to analyze DNS traffic along with server event context.

### EXAMPLE 12

```powershell
PS C:\> Get-ChildItem "C:\Logs\*.log" | Convert-DNSDebugLogFile -RemoveSourceFile -CompressOutput
```

Automated log archival: processes all logs, compresses output, and removes source files.
Ideal for scheduled log processing pipelines.

### EXAMPLE 13

```powershell
PS C:\> Convert-DNSDebugLogFile -InputFile "C:\Logs\large-dns.log" -NoDetailsParsing
```

Processes a large log file with detail parsing disabled for maximum performance.
PACKET detail blocks are skipped, keeping the Details column empty.
Use when processing very large files and detailed packet structure is not needed.

## PARAMETERS

### -CompressOutput

Compresses output CSV files into a ZIP archive after creation.

Creates a .zip file containing the generated CSV file(s), then removes the uncompressed CSV(s).
The ZIP file is created in the same directory as the output CSV with the same base name.

Benefits:
- Significantly reduces disk space (CSV files typically compress 90%+)
- Simplifies file management and archival
- Suitable for long-term storage

Example: Input 'dns.log' generates 'dns.csv' compressed to 'dns.zip', then 'dns.csv' is removed.

```yaml
Type: SwitchParameter
DefaultValue: False
SupportsWildcards: false
Aliases: []
ParameterSets:
- Name: (All)
  Position: Named
  IsRequired: false
  ValueFromPipeline: false
  ValueFromPipelineByPropertyName: false
  ValueFromRemainingArguments: false
DontShow: false
AcceptedValues: []
HelpMessage: ''
```

### -ComputerName

Specifies the value for the ComputerName column in the CSV output.
The ComputerName column is
always present in the output - if this parameter is not specified, the column will be empty.

Use this when consolidating logs from multiple DNS servers to identify the source server in
combined datasets.

Note: This is NOT a remoting parameter.
It only labels the output.
If you point -InputFile to
a UNC path, the file is read from that path (no WinRM/remote execution is performed).

```yaml
Type: String
DefaultValue: ''
SupportsWildcards: false
Aliases:
- Server
- DNSServer
- HostName
ParameterSets:
- Name: (All)
  Position: 3
  IsRequired: false
  ValueFromPipeline: false
  ValueFromPipelineByPropertyName: false
  ValueFromRemainingArguments: false
DontShow: false
AcceptedValues: []
HelpMessage: ''
```

### -Confirm

Prompts you for confirmation before running the cmdlet.

When specified, prompts for confirmation before:
- Processing each DNS debug log file
- Removing source files (when -RemoveSourceFile is specified)
- Overwriting existing output files

Useful for interactive processing when you want to control which files are processed.

```yaml
Type: SwitchParameter
DefaultValue: ''
SupportsWildcards: false
Aliases:
- cf
ParameterSets:
- Name: (All)
  Position: Named
  IsRequired: false
  ValueFromPipeline: false
  ValueFromPipelineByPropertyName: false
  ValueFromRemainingArguments: false
DontShow: false
AcceptedValues: []
HelpMessage: ''
```

### -ContextFilter

Filters which log entry types to include in the output.
Accepts single or multiple values.

DNS debug logs contain different context types:
- PACKET: DNS query and response packet information (primary data)
- EVENT: DNS server events (e.g., "The DNS server has started.")
- Note: Diagnostic notes and warnings (e.g., socket errors, internal states)
- DSPoll, Init, Lookup, Recurse, Remote, Tombstone: Additional context types

Valid values:
- 'All': Include all context types (default)
- 'Packet': Include only PACKET entries (DNS queries/responses)
- 'Event': Include only EVENT entries (server events)
- 'Note': Include only Note entries (diagnostic information)
- Any combination: Specify multiple values to include specific context types

Default: All

Examples:
- 'Packet' filters to only DNS traffic
- 'Packet','Event' includes both DNS traffic and server events
- 'Note','Event' includes diagnostic notes and server events

Note: When filtering to 'Event' or 'Note', only DateTime, ThreadId, Context, and Information
columns will contain data.
Other columns (Protocol, ClientIP, etc.) will be empty.

```yaml
Type: String[]
DefaultValue: "@('All')"
SupportsWildcards: false
Aliases: []
ParameterSets:
- Name: (All)
  Position: 5
  IsRequired: false
  ValueFromPipeline: false
  ValueFromPipelineByPropertyName: false
  ValueFromRemainingArguments: false
DontShow: false
AcceptedValues: []
HelpMessage: ''
```

### -Delimiter

Specifies the delimiter character for the CSV output.

Default: Semicolon (;)

Common alternatives: Comma (,), Tab (`t), Pipe (|)

Use semicolon in regions where comma is the decimal separator (Europe).
Use comma for standard
CSV tools and databases that expect comma-separated values.

```yaml
Type: String
DefaultValue: ;
SupportsWildcards: false
Aliases: []
ParameterSets:
- Name: (All)
  Position: 2
  IsRequired: false
  ValueFromPipeline: false
  ValueFromPipelineByPropertyName: false
  ValueFromRemainingArguments: false
DontShow: false
AcceptedValues: []
HelpMessage: ''
```

### -InputCulture

Specifies the culture/locale to use for parsing date/time values in the DNS debug log.

DNS Server debug logs use the date format of the Windows locale on the server where the log
was generated.
Use this parameter when processing logs from servers with different regional
settings.

Default: Current culture

Common examples:
- 'de-DE' or 'de-AT': German format (DD.MM.YYYY or DD/MM/YYYY)
- 'en-US': US format (MM/DD/YYYY with AM/PM)
- 'en-GB': UK format (DD/MM/YYYY with 24-hour time)
- 'sv-SE': Swedish/ISO format (YYYY-MM-DD)

```yaml
Type: CultureInfo
DefaultValue: '[System.Globalization.CultureInfo]::CurrentCulture'
SupportsWildcards: false
Aliases: []
ParameterSets:
- Name: (All)
  Position: 6
  IsRequired: false
  ValueFromPipeline: false
  ValueFromPipelineByPropertyName: false
  ValueFromRemainingArguments: false
DontShow: false
AcceptedValues: []
HelpMessage: ''
```

### -InputFile

Specifies the path to the DNS debug log file to parse.
Supports arrays for processing multiple files.

Accepts pipeline input from Get-ChildItem or other file-producing cmdlets.

```yaml
Type: String[]
DefaultValue: ''
SupportsWildcards: false
Aliases:
- FullName
- FilePath
- InputPath
- File
- Path
ParameterSets:
- Name: (All)
  Position: 0
  IsRequired: true
  ValueFromPipeline: true
  ValueFromPipelineByPropertyName: true
  ValueFromRemainingArguments: false
DontShow: false
AcceptedValues: []
HelpMessage: ''
```

### -NoDetailsParsing

Skips parsing PACKET detail blocks into structured JSON format.

When specified, PACKET records with detail blocks will have the TCP/UDP info line in the
Information column, but the Details column will remain empty.
This significantly improves
processing performance for large log files when detailed packet structure analysis is not needed.

Use this switch when:
- Processing very large log files (100MB+) and only need basic query information
- Detail structure (Message flags, DNS sections) is not required for analysis
- Maximizing parsing speed is more important than data completeness

Performance impact: Can improve processing speed by 30-50% for logs with many PACKET detail blocks.

```yaml
Type: SwitchParameter
DefaultValue: False
SupportsWildcards: false
Aliases: []
ParameterSets:
- Name: (All)
  Position: Named
  IsRequired: false
  ValueFromPipeline: false
  ValueFromPipelineByPropertyName: false
  ValueFromRemainingArguments: false
DontShow: false
AcceptedValues: []
HelpMessage: ''
```

### -OutputCulture

Specifies the culture/locale to use for formatting date/time values in the output CSV files.

Controls how DateTime values are written to the CSV.
Use this when CSV files will be consumed
by applications or systems with specific regional settings.

Default: Current culture

Common examples:
- 'en-US': US format (MM/DD/YYYY)
- 'de-DE': German format (DD.MM.YYYY)
- 'sv-SE' or InvariantCulture: ISO format (YYYY-MM-DD) for maximum compatibility

```yaml
Type: CultureInfo
DefaultValue: '[System.Globalization.CultureInfo]::CurrentCulture'
SupportsWildcards: false
Aliases: []
ParameterSets:
- Name: (All)
  Position: 7
  IsRequired: false
  ValueFromPipeline: false
  ValueFromPipelineByPropertyName: false
  ValueFromRemainingArguments: false
DontShow: false
AcceptedValues: []
HelpMessage: ''
```

### -OutputFile

Specifies the path for the output CSV file.
If not specified, uses the input filename with .csv extension
in the same directory as the input file.

Important: Must be a file path, not a directory.
If you want to use the input file's directory with
a custom name, specify the full path including filename.

```yaml
Type: String
DefaultValue: ''
SupportsWildcards: false
Aliases:
- Output
- Destination
- OutFile
- OutputPath
ParameterSets:
- Name: (All)
  Position: 1
  IsRequired: false
  ValueFromPipeline: false
  ValueFromPipelineByPropertyName: false
  ValueFromRemainingArguments: false
DontShow: false
AcceptedValues: []
HelpMessage: ''
```

### -OutputType

Specifies the type of output to generate.

Valid values:
- 'CSV': Generate only the data file with all parsed log entries
- 'Statistic': Generate only the statistics files with aggregated metrics
- 'Both': Generate both data and statistics files (default)

Default: Both

When statistics are generated, two separate files are created:
- '_Statistic.csv': Summary counts per context type per day (Date, Context, Count, ComputerName)
- '_PacketStatistic.csv': Detailed PACKET counts per day by client IP, protocol, direction,
  and query type (Date, ClientIP, Protocol, Direction, QuestionType, Count, ComputerName)

```yaml
Type: String
DefaultValue: Both
SupportsWildcards: false
Aliases: []
ParameterSets:
- Name: (All)
  Position: 4
  IsRequired: false
  ValueFromPipeline: false
  ValueFromPipelineByPropertyName: false
  ValueFromRemainingArguments: false
DontShow: false
AcceptedValues: []
HelpMessage: ''
```

### -RemoveSourceFile

Removes the source DNS debug log file after successful processing.

Use this for automated log processing pipelines or disk space management.
The source file is
only removed if processing completes successfully and all output files are created.

Safety: Cannot be used with -SkipHeaderValidation to prevent accidental deletion of invalid files.

Warning: Source files are permanently deleted.
Ensure output files are valid before using this option.

```yaml
Type: SwitchParameter
DefaultValue: False
SupportsWildcards: false
Aliases: []
ParameterSets:
- Name: (All)
  Position: Named
  IsRequired: false
  ValueFromPipeline: false
  ValueFromPipelineByPropertyName: false
  ValueFromRemainingArguments: false
DontShow: false
AcceptedValues: []
HelpMessage: ''
```

### -SkipHeaderValidation

Bypasses the DNS debug log header validation check.

By default, the cmdlet validates that input files have a valid DNS Server debug log header.
Use this switch to process files without validation, which can be useful for:
- Modified or custom log formats
- Troubleshooting validation issues
- Non-standard or pre-processed logs

Warning: May result in processing errors if the file is not a valid DNS log.

```yaml
Type: SwitchParameter
DefaultValue: False
SupportsWildcards: false
Aliases: []
ParameterSets:
- Name: (All)
  Position: Named
  IsRequired: false
  ValueFromPipeline: false
  ValueFromPipelineByPropertyName: false
  ValueFromRemainingArguments: false
DontShow: false
AcceptedValues: []
HelpMessage: ''
```

### -WhatIf

Shows what would happen if the cmdlet runs.
The cmdlet is not run.

When specified, displays detailed information about the operations that would be performed
without actually executing them.
Useful for:
- Previewing which files would be processed
- Verifying output file paths before processing
- Testing scripts before running in production

```yaml
Type: SwitchParameter
DefaultValue: ''
SupportsWildcards: false
Aliases:
- wi
ParameterSets:
- Name: (All)
  Position: Named
  IsRequired: false
  ValueFromPipeline: false
  ValueFromPipelineByPropertyName: false
  ValueFromRemainingArguments: false
DontShow: false
AcceptedValues: []
HelpMessage: ''
```

### CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable,
-InformationAction, -InformationVariable, -OutBuffer, -OutVariable, -PipelineVariable,
-ProgressAction, -Verbose, -WarningAction, and -WarningVariable. For more information, see
[about_CommonParameters](https://go.microsoft.com/fwlink/?LinkID=113216).

## INPUTS

### System.String[]

## NOTES

Version  : 1.7.1.1
Author   : Andi Bellstedt, Copilot
Date     : 2026-01-26
Keywords : Microsoft Windows Server, DNSServer, DNS, DebugLog, LogParser

## RELATED LINKS

- [github.com/AndiBellstedt/DNSServer.DebugLogParser](https://github.com/AndiBellstedt/DNSServer.DebugLogParser)
