Project

General

Profile

Actions

Feature #4751

closed

dns/eve: add 'HTTPS' type logging

Added by Victor Julien about 3 years ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:
Beginner, Needs backport to 6.0, Rust

Description

{"timestamp":"2021-10-12T10:17:37.702061+0200","flow_id":865976079988333,"pcap_cnt":1,"event_type":"dns","src_ip":"192.168.0.47","src_port":61954,"dest_ip":"192.168.0.1","dest_port":53,"proto":"UDP","dns":{"type":"query","id":4220,"rrname":"46-105-202-126.any.cdn.anycast.me","rrtype":"65","tx_id":0}}

rrtype: 65 instead of HTTPS


Files

dns-in-rec.pcap (133 Bytes) dns-in-rec.pcap Victor Julien, 10/12/2021 08:24 AM
Screenshot from 2021-10-12 10-25-04.png (78.8 KB) Screenshot from 2021-10-12 10-25-04.png Victor Julien, 10/12/2021 08:25 AM

Subtasks 1 (0 open1 closed)

Feature #6282: dns/eve: add 'HTTPS' type logging (6.0.x backport)ClosedJason IshActions
Actions

Also available in: Atom PDF