# No dns.log after update from 6.0.4 to 6.0.6 or 6.0.8

**URL:** <https://community.zeek.org/t/no-dns-log-after-update-from-6-0-4-to-6-0-6-or-6-0-8/7612>\
**Category:** Zeek\
**Created:** [October 22, 2024, 12:30pm UTC](https://community.zeek.org/t/no-dns-log-after-update-from-6-0-4-to-6-0-6-or-6-0-8/7612 "2024-10-22T12:30:22Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![0x4A6F686E](https://avatars.discourse-cdn.com/v4/letter/0/b3f665/32.png) [@0x4A6F686E](https://community.zeek.org/u/0x4A6F686E)\
**Post date:** [October 22, 2024, 12:30pm UTC](https://community.zeek.org/t/no-dns-log-after-update-from-6-0-4-to-6-0-6-or-6-0-8/7612/1 "2024-10-22T12:30:22Z")

</div>

Hi guys,  
I just upgraded Zeek on my test server from version 6.0.4 to 6.0.6 without any change in the Zeek confguration file. I noticed that dns.log no longer appeared in the directory with the current logs.  
Tried version 6.0.8 instead. Same behaviour. Switched back to 6.0.4 and now the dns.log is there.

I read through all the release notes starting with 6.0.5 but didn’t see anything that could explain this behaviour. Build instructions used for all versions were the same. No errors in stdout.log or stderr.log.

Anyone any idea?

Cheers, John

---

<div class="post-metadata">

**Author:** ![awelzel](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/awelzel/32/609_2.png) [@awelzel](https://community.zeek.org/u/awelzel)\
**Post date:** [October 22, 2024, 2:44pm UTC](https://community.zeek.org/t/no-dns-log-after-update-from-6-0-4-to-6-0-6-or-6-0-8/7612/2 "2024-10-22T14:44:44Z")

</div>

> [@0x4A6F686E](#):
>
> Anyone any idea?

Strange! If it’s a test server, can you update again and let it run for a bit longer?

Is there anything in `reporter.log` or on stderr/stdout of the logger processes?

Are you running zeekctl and possibly configured with multiple loggers? There’s an issue with the `current/` symlink, maybe it’s causing confusion?

> <https://github.com/zeek/zeekctl/issues/64>
>
> the \[quickstart guide\](https://docs.zeek.org/en/master/quickstart.html) says:
> 
> …
> \* \`$PREFIX/logs/\`
> - As the name suggests it is the default logs directory where Zeek stores the rotated logs from the current directory:
> \* \`current\`
> + It is a symlink to the spool directory that is defined in the zeekctl.cfg configuration file. It contains the active log files that Zeek currently writes to when running via ZeekControl.
> 
> However, when I have multiple loggers defined in my node.cfg:
> 
> \`\`\`
> \[manager\]
> type=manager
> host=localhost
> 
> \[logger-1\]
> type=logger
> host=localhost
> 
> \[logger-2\]
> type=logger
> host=localhost
> 
> \[proxy-1\]
> type=proxy
> host=localhost
> 
> \[worker-1\]
> type=worker
> host=localhost
> interface=enp0s25
> lb\_procs=4
> lb\_method=custom
> af\_packet\_fanout\_id=1
> af\_packet\_fanout\_mode=AF\_Packet::FANOUT\_HASH
> af\_packet\_buffer\_size=67108864
> \`\`\`
> 
> I end up with \`logger-1\` and \`logger-2\` directories in the \`spool\` directory, as expected. However, \`current\` is still just a symlink to \`logger-1\`. There's no access to \`logger-2\` except through the \`spool\` directory directly.
> 
> Not sure what the right thing to do here is... \`current-1\` and \`current-2\`, etc. symlinks? Or maybe just update the documentation.

---

<div class="post-metadata">

**Author:** ![0x4A6F686E](https://avatars.discourse-cdn.com/v4/letter/0/b3f665/32.png) [@0x4A6F686E](https://community.zeek.org/u/0x4A6F686E)\
**Post date:** [October 23, 2024, 6:21am UTC](https://community.zeek.org/t/no-dns-log-after-update-from-6-0-4-to-6-0-6-or-6-0-8/7612/3 "2024-10-23T06:21:41Z")

</div>

Hi Arne,

nothing in the other logs either. I’m using docker containers so it is extremely easy to switch between versions. Letting it run for a longer period of time is not necessary because this test server gets the same data feed as one of the production servers and receives around 600k DNS requests/hour 🙂

I’ll go through the git logs to see if anything changed in the docker build files and will also build another 6.0.4 container using the current build files just to find out what I can reproduce, or not.

Keep you posted!

John

---

<div class="post-metadata">

**Author:** ![awelzel](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/awelzel/32/609_2.png) [@awelzel](https://community.zeek.org/u/awelzel)\
**Post date:** [October 23, 2024, 8:25am UTC](https://community.zeek.org/t/no-dns-log-after-update-from-6-0-4-to-6-0-6-or-6-0-8/7612/4 "2024-10-23T08:25:50Z")

</div>

Hey,

are other logs produced? Do you see `conn.log` entries with port 53? Maybe check on CPU usage of the processes (worker, loggers, etc)

🤞

---

<div class="post-metadata">

**Author:** ![0x4A6F686E](https://avatars.discourse-cdn.com/v4/letter/0/b3f665/32.png) [@0x4A6F686E](https://community.zeek.org/u/0x4A6F686E)\
**Post date:** [October 24, 2024, 3:20pm UTC](https://community.zeek.org/t/no-dns-log-after-update-from-6-0-4-to-6-0-6-or-6-0-8/7612/5 "2024-10-24T15:20:54Z")

</div>

A few remarkable things, besides there being no dns.log

- there is a lot of DNS traffic (udp port 53) to be found in the conn.log, however the field “service”:dns is missing;
- other mentiongs like service:http are present;
- in the known\_services.log there isn’t any mentioning of any DNS service, unlike other installations;
- I recompiled 6.0.4 in a container using our current Dockerfiles and unfortunately the same behaviour so the problem must be somewhere else in the entire setup, a library, an installed package, etc.

I’m now trying to recreate a brand new container using version 6.0.4 stripped down to roughly the same instructions as available inside the docker/ source directory. I took this as a starting point earlier and there aren’t many differences but I want to start as clean as possible.

To be continued…

---

<div class="post-metadata">

**Author:** ![awelzel](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/awelzel/32/609_2.png) [@awelzel](https://community.zeek.org/u/awelzel)\
**Post date:** [October 25, 2024, 7:28am UTC](https://community.zeek.org/t/no-dns-log-after-update-from-6-0-4-to-6-0-6-or-6-0-8/7612/6 "2024-10-25T07:28:33Z")

</div>

Hmm a packet checksum issue? Do thing change if `ignore_checksums` set to `T`? Maybe some `ethtool` settings that enable/disable checksum offloading have changed?

Anything in weird.log that might be indicative?

---

<div class="post-metadata">

**Author:** ![0x4A6F686E](https://avatars.discourse-cdn.com/v4/letter/0/b3f665/32.png) [@0x4A6F686E](https://community.zeek.org/u/0x4A6F686E)\
**Post date:** [October 25, 2024, 11:07am UTC](https://community.zeek.org/t/no-dns-log-after-update-from-6-0-4-to-6-0-6-or-6-0-8/7612/7 "2024-10-25T11:07:36Z")

</div>

I reran all steps from scratch. I now have a running 6.0.4 inside a container with the same compilation options as I have in production. So far so good.

Next step is to add the Zeek packages we normally use, one by one to see which of those causes this weird problem.

Again, to be continued…

---

<div class="post-metadata">

**Author:** ![0x4A6F686E](https://avatars.discourse-cdn.com/v4/letter/0/b3f665/32.png) [@0x4A6F686E](https://community.zeek.org/u/0x4A6F686E)\
**Post date:** [October 28, 2024, 2:42pm UTC](https://community.zeek.org/t/no-dns-log-after-update-from-6-0-4-to-6-0-6-or-6-0-8/7612/8 "2024-10-28T14:42:58Z")

</div>

I found it: adding zeek/spicy-analyzers causes the problems.  
This is what is being installed:

```auto
+ zkg install --force zeek/spicy-analyzers
Installing "http://github.com/zeek/spicy-zip"
Installed "http://github.com/zeek/spicy-zip" (v0.0.6)
Loaded "http://github.com/zeek/spicy-zip"
Installing "http://github.com/zeek/spicy-tftp"
Installed "http://github.com/zeek/spicy-tftp" (v0.0.5)
Loaded "http://github.com/zeek/spicy-tftp"
Installing "http://github.com/zeek/spicy-png"
Installed "http://github.com/zeek/spicy-png" (v0.0.6)
Loaded "http://github.com/zeek/spicy-png"
Installing "http://github.com/zeek/spicy-pe"
Installed "http://github.com/zeek/spicy-pe" (v0.0.12)
Loaded "http://github.com/zeek/spicy-pe"
Installing "http://github.com/zeek/spicy-http"
Installed "http://github.com/zeek/spicy-http" (v0.0.9)
Loaded "http://github.com/zeek/spicy-http"
Installing "http://github.com/zeek/spicy-dns"
Installed "http://github.com/zeek/spicy-dns" (v0.0.9)
Loaded "http://github.com/zeek/spicy-dns"
Installing "http://github.com/zeek/spicy-dhcp"
Installed "http://github.com/zeek/spicy-dhcp" (v0.0.11)
Loaded "http://github.com/zeek/spicy-dhcp"
Installing "zeek/zeek/spicy-analyzers"
Installed "zeek/zeek/spicy-analyzers" (v0.2.33)

```

Logically thinking my guess is that spicy-dns might be the problem. I tried to install it seperately instead of the spicy-analyzers (zkg install --force zeek/spicy-dns) but that fails. The only message I get is “error: failed to run tests for zeek/zeek/spicy-dns: test\_command failed with exit code 1”.  
Haven’t had the time to figure out exactly why. Everything runs inside containers so it makes debugging a bit harder.

At least I now know what happened.

John
