[Bro] Questions about Bro's DNS Parser

Seth Hall hall.692 at osu.edu
Wed Feb 10 13:31:53 PST 2010


On Feb 9, 2010, at 10:12 AM, daniela.miao at utoronto.ca wrote:

> Problem is, the output file after running this script without the
> "@load global-ext" line, is exactly the same as what I was getting
> before. I'm still not receiving the error codes that some of the
> response packets contain.


Sorry I didn't explain that better.  The scripts located at my github  
repository have several dependencies among them.  You should probably  
just grab all of the scripts there and load the script you want.  You  
also need to load the logging.dns-ext.bro script in order for dns- 
ext.bro to actually output any logs.

   .Seth

---
Seth Hall
Network Security - Office of the CIO
The Ohio State University
Phone: 614-292-9721




More information about the Bro mailing list