This page describes how to create and modify a DNS threat detector to monitor VPC networks for malicious, internet-bound DNS activity.
For more information about DNS threat detection, see DNS Armor overview.
DNS threat monitoring can impact your billing. See Cloud DNS Pricing for more information.
Before you begin
Complete the following before you create a DNS threat detector.
- Enable the Network Security API in your project.
- Make sure that you have the required roles to enable a DNS threat detector.
- If you want to use Google Cloud CLI to perform tasks, update Google Cloud CLI to the latest version.
Create DNS threat detector
To create a DNS threat detector for all of your VPC networks in a project, complete the following steps. Any new VPC networks added to the project are monitored automatically.
You can have only one DNS threat detector enabled for a project.