mirror of https://github.com/OISF/suricata
output-json-alert: add dns info
This changes LogQuery and LogAnswer functions returning a json object instead of writing it in a log file. In this way it's possible to reuse them to add dns info into an alert. The following is an alert record with dns: { "timestamp": "2017-07-31T15:01:17.885281+0200", "event_type": "alert", "src_ip": "8.8.8.8", ... "dns": { "query": [ { "type": "query", "id": 25394, "rrname": "notifications.google.com", "rrtype": "A", "tx_id": 0 } ], "answer": { "type": "answer", "id": 25394, "rcode": "NOERROR", "answers": [ { "rrname": "notifications.google.com", "rrtype": "CNAME", "ttl": 3599, "rdata": "plus.l.google.com" }, { "rrname": "plus.l.google.com", "rrtype": "A", "ttl": 299, "rdata": "216.58.205.174" } ] } } }pull/3288/head
parent
6231ffc110
commit
92db7be502
Loading…
Reference in New Issue