I am currently doing a listing of Suricata rules for my company, and I found that the ones in dns-events.rules are using the app-layer-event field. With a bit of researches, it appears that these app-layer-events are described in the app-layer-dns.c file, which does not exists anymore. Do these rules still work, and if yes how ?
Thanks for your help
What version of Suricata are you looking at?
master, you’ll find these events in
rust/src/dns/dns.rs. Previous versions of Suricata – 4.1.x and 5.0.x – had the same information in
Hello Jeff, thanks for your reply
I use version 4.1.2, but had a look at Github master branch, thus not the good versions. Had a look at the correct branch and found the file !