A little more confusion with Intel

I see the dns request is for “www.yahoo.com”, however the entry in your intel-1.dat is for “yahoo.com
Not sure if Bro intel framework works with the sub-domains lookup as well for intel.
Try adding “www.yahoo.com” in your intel-1.dat , and see if intel.log triggers.

Ya we discovered that worked thanks Fatema…but that defeats the point of “domain” in the intel file :frowning: