Created
November 2, 2012 22:59
-
-
Save mavam/4004865 to your computer and use it in GitHub Desktop.
DNS lookup in Bro using the when statement
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
when (local result = lookup_addr("www.bro-ids.org")) | |
{ | |
for (addr in result) | |
print addr; | |
} |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
The
lookup_addr
function takes an ip address as its argument, and performs a reverse-dns lookup. The function used here should belookup_hostname
.https://www.bro.org/sphinx/scripts/base/bif/bro.bif.bro.html#id-lookup_hostname