dns_HINFO_reply event was never being generated.

On top of that, I modified the event to pass the relevant fields from the DNS message.
This commit is contained in:
Vlad Grigorescu 2021-07-15 09:56:38 -05:00
parent eeee2c41a3
commit 15b294098c
5 changed files with 36 additions and 10 deletions

View file

@ -0,0 +1,2 @@
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
HINFO, [id=51592, opcode=0, rcode=0, QR=T, AA=T, TC=F, RD=T, RA=T, Z=0, num_queries=1, num_answers=1, num_auth=0, num_addl=1], [answer_type=1, query=zeek.example.net, qtype=13, qclass=1, TTL=1.0 hr], INTEL-386, Windows