DNS: Log the type number for the DNS_RR_unknown_type weird.

This commit is contained in:
Vlad Grigorescu 2015-03-18 13:31:12 -04:00
parent 5e2defebe5
commit 01e5de8234
2 changed files with 4 additions and 4 deletions

View file

@ -308,7 +308,7 @@ int DNS_Interpreter::ParseAnswer(DNS_MsgInfo* msg,
analyzer->ConnectionEvent(dns_unknown_reply, vl);
}
analyzer->Weird("DNS_RR_unknown_type");
analyzer->Weird("DNS_RR_unknown_type", fmt("%d", msg->atype));
data += rdlength;
len -= rdlength;
status = 1;

View file

@ -3,10 +3,10 @@
#empty_field (empty)
#unset_field -
#path weird
#open 2014-02-13-20-36-35
#open 2015-03-18-17-30-43
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p name addl notice peer
#types time string addr port addr port string string bool string
1363716396.798286 CXWv6p3arKYeMETxOg 55.247.223.174 27285 222.195.43.124 53 DNS_RR_unknown_type - F bro
1363716396.798286 CXWv6p3arKYeMETxOg 55.247.223.174 27285 222.195.43.124 53 DNS_RR_unknown_type 46 F bro
1363716396.798374 CXWv6p3arKYeMETxOg 55.247.223.174 27285 222.195.43.124 53 dns_unmatched_reply - F bro
1363716396.798374 - - - - - dns_unmatched_msg - F bro
#close 2014-02-13-20-36-35
#close 2015-03-18-17-30-44