Project

General

Profile

Actions

Bug #4178

open

DNS Query triggers alert but no output in alert-debug.log

Added by Andreas Herz almost 4 years ago. Updated over 1 year ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

If you run this rule:

alert dns $HOME_NET any -> any any (msg:"BAR"; dns.query; content:"suricata-ids.org"; sid:1337; rev:1;)

against the attached pcap or do the lookup `dig -t A suricata-ids.org` and listen on the interface you will trigger the correct alert but won't see any alert-debug.log output.


Files

test.pcap (274 Bytes) test.pcap Andreas Herz, 11/23/2020 09:51 PM
Actions

Also available in: Atom PDF