Re: Zeek/Bro DNS log missing type

Jon Siwek <[email protected]>
Newsgroups gmane.comp.security.detection.bro
Message-ID <CAMzgZ0JMzveu6Ce3ug1UJoSb+zwZB_o2GMXg-uyKTngWabQ16g@mail.gmail.com>
On Fri, Aug 16, 2019 at 9:18 AM Michael Gez <[email protected]> wrote:

> If I look using Wireshark with the same PCAP I see that the type “A” is present, as I would expect it to be.
> However, the resulting Zeek dns.log is missing that field in particular.
> I need Zeek to parse this type field out so I know to look into the domain visited to make sure it is legitimate.
>
> Are there any known issues with the DNS parser, or any known solutions to this particular problem?

Nothing comes to mind.  It's easiest to investigate further if you can
share an example pcap that reproduces the unexpected behavior.

- Jon

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.