DNS App Layer Events

Hello everyone,

I am currently doing a listing of Suricata rules for my company, and I found that the ones in dns-events.rules are using the app-layer-event field. With a bit of researches, it appears that these app-layer-events are described in the app-layer-dns.c file, which does not exists anymore. Do these rules still work, and if yes how ?

Thanks for your help

Hi,
What version of Suricata are you looking at?

For master, you’ll find these events in rust/src/dns/dns.rs. Previous versions of Suricata – 4.1.x and 5.0.x – had the same information in src/app-layer-dns-common.c

Hello Jeff, thanks for your reply
I use version 4.1.2, but had a look at Github master branch, thus not the good versions. Had a look at the correct branch and found the file !

Thanks again