<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Microsoft DNS in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-DNS/m-p/389774#M69762</link>
    <description>&lt;P&gt;This might not be the right place for this question but I see DNS request that seem to have a recordtype = ZERO in my splunk logs.  I don't know what would be causing this, it doesn't seem like a valid type that DNS would even let you query for.&lt;/P&gt;

&lt;P&gt;2/13/2019 11:48:59 AM 14E8 PACKET  000000A722BE61B0 UDP Rcv 10.10.10.106   d751   Q [0001   D   NOERROR] ZERO  &lt;A href="http://www.microsoft.com"&gt;www.microsoft.com&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I am seeing tons of these from different client on different servers for different queries. Doesn't seem like they get passed on to the downstream DNS for resolution, but I don't know if this ZERO record is a hiccup on the DNS servers or with clients there are times when  see thousands of them and normally it is like a few hundred.  Anyone else have Microsoft DNS logs and see random queries for record type ZERO?&lt;/P&gt;

&lt;P&gt;Thank you,&lt;BR /&gt;
Brian Kirk&lt;/P&gt;</description>
    <pubDate>Fri, 15 Feb 2019 21:24:09 GMT</pubDate>
    <dc:creator>bkirk</dc:creator>
    <dc:date>2019-02-15T21:24:09Z</dc:date>
    <item>
      <title>Microsoft DNS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-DNS/m-p/389774#M69762</link>
      <description>&lt;P&gt;This might not be the right place for this question but I see DNS request that seem to have a recordtype = ZERO in my splunk logs.  I don't know what would be causing this, it doesn't seem like a valid type that DNS would even let you query for.&lt;/P&gt;

&lt;P&gt;2/13/2019 11:48:59 AM 14E8 PACKET  000000A722BE61B0 UDP Rcv 10.10.10.106   d751   Q [0001   D   NOERROR] ZERO  &lt;A href="http://www.microsoft.com"&gt;www.microsoft.com&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I am seeing tons of these from different client on different servers for different queries. Doesn't seem like they get passed on to the downstream DNS for resolution, but I don't know if this ZERO record is a hiccup on the DNS servers or with clients there are times when  see thousands of them and normally it is like a few hundred.  Anyone else have Microsoft DNS logs and see random queries for record type ZERO?&lt;/P&gt;

&lt;P&gt;Thank you,&lt;BR /&gt;
Brian Kirk&lt;/P&gt;</description>
      <pubDate>Fri, 15 Feb 2019 21:24:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-DNS/m-p/389774#M69762</guid>
      <dc:creator>bkirk</dc:creator>
      <dc:date>2019-02-15T21:24:09Z</dc:date>
    </item>
  </channel>
</rss>

