new to bro, a few questions

Hi, I’m new to Bro and I’m wondering how I can do a couple of things:

  1. I’d like to basically disable all of the various rules and detection stuff.
  2. I’d like to create a simple rule that detects say DNS packets with in the query or answer

Figure it would be best to start simple and then build up rules (either my own, or others) as I need them. Sort of a K&R “Hello World” approach…

Any specifics would be much appreciated.

Thank you

You may want to look at Bro’s “bare mode”. It starts Bro without many of Bro’s features.