[Bro] Problem with QR field in dns log
sheharbano.k at gmail.com
Tue Apr 10 23:30:43 PDT 2012
Dear Bro Team,
I was working with some DNS logs and wanted to look at total number of DNS
MX queries and responses. I used the usual bro-cut/awk/sort/uniq commands
and turned out that there are absolutely no DNS responses within the log. I
know that this is not true, and confirmed via tshark.
I looked at script /base/protocols/dns.bro. In the definition of what goes
into the log, the entry says
## Whether the message is a query (F) or response (T).
QR: bool &log &default=F;
which sounds good. But it seems that QR has not been assigned a value
anywhere in the rest of the code, therefore the default value F is
displayed whether it's a query or a response. Maybe QR should become 'T' in
all the dns_reply(AA/MX/....) events in the script.
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Bro