--- /dev/null
+pcap: ../../dns-udp-eve-log-query-only-v1/dns-udp-google.com-a-aaaa-mx.pcap
+
+requires:
+ min-version: 8
+
+checks:
+ - filter:
+ count: 1
+ match:
+ dns.type: request
+ dns.queries[0].rrtype: AAAA
+ - filter:
+ count: 1
+ match:
+ dns.type: response
+ dns.answers[0].rrtype: AAAA
+ dns.answers.__len: 1
+ - filter:
+ count: 0
+ match:
+ dns.rrtype: A
--- /dev/null
+Test custom eve DNS logging by configuring it to log only AAAA
+records, and verifying that only AAAA records are logged.
--- /dev/null
+%YAML 1.1
+---
+
+outputs:
+ - eve-log:
+ enabled: yes
+ filetype: regular
+ filename: eve.json
+ types:
+ - dns:
+ version: 2
+ types: [aaaa]
-pcap: ../dns-udp-eve-log-query-only-v1/dns-udp-google.com-a-aaaa-mx.pcap
-
-requires:
- features:
- - HAVE_LIBJANSSON
+pcap: ../../../dns-udp-eve-log-query-only-v1/dns-udp-google.com-a-aaaa-mx.pcap
checks:
- filter: