DNS Plugin

This plugin dissects DNS traffic and saves it in dump files as well export the information via NetFlow/IPFIX using the following information elements.

[NFv9 57677][IPFIX 35632.205][Len 256 varlen] %DNS_QUERY        DNS query
[NFv9 57678][IPFIX 35632.206][Len 2] %DNS_QUERY_ID              DNS query transaction Id
[NFv9 57679][IPFIX 35632.207][Len 1] %DNS_QUERY_TYPE            DNS query type (e.g. 1=A, 2=NS..)
[NFv9 57680][IPFIX 35632.208][Len 1] %DNS_RET_CODE              DNS return code (e.g. 0=no error)
[NFv9 57681][IPFIX 35632.209][Len 1] %DNS_NUM_ANSWERS           DNS # of returned answers
[NFv9 57824][IPFIX 35632.352][Len 4] %DNS_TTL_ANSWER            TTL of the first A record (if any)
[NFv9 57870][IPFIX 35632.398][Len 256 varlen] %DNS_RESPONSE     DNS response(s)

Using –dns-dump-dir <dump dir> it is possible to specify where the DNS dump files will be saved. Each file is up to 1000 lines long and when is completed a new file will be created.