# How to modify dns.log

**URL:** <https://community.zeek.org/t/how-to-modify-dns-log/3444>\
**Category:** Zeek\
**Created:** [January 23, 2015, 1:43pm UTC](https://community.zeek.org/t/how-to-modify-dns-log/3444 "2015-01-23T13:43:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fasf\_safas](https://avatars.discourse-cdn.com/v4/letter/f/f05b48/32.png) [@fasf\_safas](https://community.zeek.org/u/fasf_safas)\
**Post date:** [January 23, 2015, 1:43pm UTC](https://community.zeek.org/t/how-to-modify-dns-log/3444/1 "2015-01-23T13:43:20Z")

</div>

Hi,

i want to introduce two new fields in dns.log: i’ve tried to use a code like this:

-----script.bro------  
redef record DNS::Info += {  
foo: bool &optional &log;  
};

event DNS::log\_dns (rec: DNS::Info)  
{  
if(condition)  
rec$foo = T;  
}

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [January 23, 2015, 5:11pm UTC](https://community.zeek.org/t/how-to-modify-dns-log/3444/2 "2015-01-23T17:11:41Z")

</div>

The event should should handle is the one that has the data you’re basing your condition (in your example) off of. The log events are too late. The data is already set and gone at that point. I think there might be some justification for turning those log events into hooks so you could actually modify it in place before it’s actually logged (we’ll discuss this internally).

What is the condition you’re working with in your dns log?

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:42pm UTC](https://community.zeek.org/t/how-to-modify-dns-log/3444/3 "2022-05-06T15:42:23Z")

</div>


