[Oisf-users] dns parser, pcre and logging options

Justin Cinkelj justin.cinkelj at xlab.si
Tue May 14 18:33:28 UTC 2013

I'm trying dsn parser from https://github.com/inliniac/suricata.git, 

alert dnsudp any any -> any (sid:5003008; pcre:"/ttrt.com/", 
rev:1; )
triggers on
dig @ 'ttrt.com'
dig @ 'ttrt_com'

So I try to escape the '.', but
alert dnsudp any any -> any (sid:5003008; pcre:"/ttrt\.com/", 
rev:1; )
triggers on
dig @ 'ttrt\.com'
and not on
dig @ 'ttrt.com'

I must be missing something obvious?

In fast.log I get 'only':
05/14/2013-19:29:44.421810  [**] [1:5003005:1] (null) [**] 
[Classification: (null)] [Priority: 3] {UDP} ->
Additional details are not shown any more (as in 
) ?
Are there some dns logging configuration options?


More information about the Oisf-users mailing list