Skip to content

Instantly share code, notes, and snippets.

@philhagen
Last active October 12, 2021 20:45
Show Gist options
  • Star 1 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save philhagen/8549ef52b69dfa245fe797b647ed0f7d to your computer and use it in GitHub Desktop.
Save philhagen/8549ef52b69dfa245fe797b647ed0f7d to your computer and use it in GitHub Desktop.
Zeek dns.log Sample for SANS JSON and jq Handout
{"ts":1602265824.123071,"uid":"CHFRflzsgM15k9et4","id.orig_h":"192.168.75.169","id.orig_p":58506,"id.resp_h":"192.168.75.1","id.resp_p":53,"proto":"udp","trans_id":50763,"rtt":0.022633075714111329,"query":"www.sansgear.com","qclass":1,"qclass_name":"C_INTERNET","qtype":1,"qtype_name":"A","rcode":0,"rcode_name":"NOERROR","AA":false,"TC":false,"RD":true,"RA":true,"Z":0,"answers":["vhost1.identityvector.com","70.32.97.206"],"TTLs":[3600.0,3600.0],"rejected":false}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment