Re: Zeek/Bro DNS log missing type
Jon Siwek <[email protected]>
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CAMzgZ0JMzveu6Ce3ug1UJoSb+zwZB_o2GMXg-uyKTngWabQ16g@mail.gmail.com> |
On Fri, Aug 16, 2019 at 9:18 AM Michael Gez <[email protected]> wrote: > If I look using Wireshark with the same PCAP I see that the type “A” is present, as I would expect it to be. > However, the resulting Zeek dns.log is missing that field in particular. > I need Zeek to parse this type field out so I know to look into the domain visited to make sure it is legitimate. > > Are there any known issues with the DNS parser, or any known solutions to this particular problem? Nothing comes to mind. It's easiest to investigate further if you can share an example pcap that reproduces the unexpected behavior. - Jon _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek