Recently I’ve been trying to upgrade from Zeek 3 to the latest Zeek 5 version.
When I look at the dns.log on both versions, Zeek 5 log is a bit smaller.
I noticed that version 5 is missing the lines where the answers field is unknown type=65 and unknown type=64. for some reason Zeek doesn’t show it on version 5
example of one of the missing lines:
Why Zeek 5 doesn’t show those lines in dns.log?