<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Query doesnt look right in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/DNS-Query-doesnt-look-right/m-p/136561#M184753</link>
    <description>&lt;P&gt;The Rcv from external IPs are showing incoming packets from external DNS servers. The DNS server you're monitoring is performing recursive queries, so it has to get the answer for external domains from an external DNS server. Your log is showing you all incoming and outgoing DNS packets.,The Rcv lines from external addresses are showing you responses from external DNS servers. Since the DNS server you're monitoring is a recursive resolver, it will ask other DNS servers on the Internet for answers. The log is just showing you all the incoming and outgoing packets related to the query.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Oct 2014 14:52:47 GMT</pubDate>
    <dc:creator>kogane</dc:creator>
    <dc:date>2014-10-03T14:52:47Z</dc:date>
    <item>
      <title>DNS Query doesnt look right</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DNS-Query-doesnt-look-right/m-p/136560#M184752</link>
      <description>&lt;P&gt;Hi All, &lt;/P&gt;

&lt;P&gt;Not sure im in the right place for this, but i'm hoping someone understands.&lt;/P&gt;

&lt;P&gt;I've configured splunk to show me DNS queries to bad domains, which is great. But it raises more questions than answers.&lt;/P&gt;

&lt;P&gt;As I understand Rcv lines are the IP where the request came from and Snd are what the DNS server gave as an answer. My logic is that I should only have Rcv lines from internal addresses ? &lt;/P&gt;

&lt;P&gt;Why might I see Rcv from external addresses please ? &lt;/P&gt;

&lt;P&gt;1 » 09/11/2013 10:00:45.000  20131109 10:00:45 1570 PACKET  UDP Snd 10.40.0.44      2f71 R Q [0084 A     NOERROR] .otnnetwork.net.host=builbdc1   Options|  sourcetype=dns_queries   Options|  source=c:\windows\system32\dns\dns.log   Options &lt;/P&gt;

&lt;P&gt;2 » 09/11/2013 10:00:45.000  20131109 10:00:45 1570 PACKET  UDP Rcv 205.251.195.116 21e9 R Q [0084 A     NOERROR] .otnnetwork.net.host=builbdc1   Options|  sourcetype=dns_queries   Options|  source=c:\windows\system32\dns\dns.log   Options &lt;/P&gt;

&lt;P&gt;3 » 09/11/2013 10:00:45.000  20131109 10:00:45 153C PACKET  UDP Snd 205.251.195.116 21e9   Q [0000       NOERROR] .otnnetwork.net.host=builbdc1   Options|  sourcetype=dns_queries   Options|  source=c:\windows\system32\dns\dns.log   Options &lt;/P&gt;

&lt;P&gt;4 » 09/11/2013 10:00:45.000  20131109 10:00:45 153C PACKET  UDP Rcv 192.12.94.30    21e9 R Q [0080       NOERROR] .otnnetwork.net.host=builbdc1   Options|  sourcetype=dns_queries   Options|  source=c:\windows\system32\dns\dns.log   Options &lt;/P&gt;

&lt;P&gt;5 » 09/11/2013 10:00:45.000  20131109 10:00:45 153C PACKET  UDP Snd 192.12.94.30    21e9   Q [0000       NOERROR] .otnnetwork.net.host=builbdc1   Options|  sourcetype=dns_queries   Options|  source=c:\windows\system32\dns\dns.log   Options &lt;/P&gt;

&lt;P&gt;6 » 09/11/2013 10:00:45.000  20131109 10:00:45 153C PACKET  UDP Rcv 10.40.0.44      2f71   Q [0001   D   NOERROR] .otnnetwork.net.host=builbdc1   Options|  sourcetype=dns_queries   Options|  source=c:\windows\system32\dns\dns.log   Options &lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Derek&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2013 13:51:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DNS-Query-doesnt-look-right/m-p/136560#M184752</guid>
      <dc:creator>DerekKing</dc:creator>
      <dc:date>2013-11-11T13:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query doesnt look right</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DNS-Query-doesnt-look-right/m-p/136561#M184753</link>
      <description>&lt;P&gt;The Rcv from external IPs are showing incoming packets from external DNS servers. The DNS server you're monitoring is performing recursive queries, so it has to get the answer for external domains from an external DNS server. Your log is showing you all incoming and outgoing DNS packets.,The Rcv lines from external addresses are showing you responses from external DNS servers. Since the DNS server you're monitoring is a recursive resolver, it will ask other DNS servers on the Internet for answers. The log is just showing you all the incoming and outgoing packets related to the query.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2014 14:52:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DNS-Query-doesnt-look-right/m-p/136561#M184753</guid>
      <dc:creator>kogane</dc:creator>
      <dc:date>2014-10-03T14:52:47Z</dc:date>
    </item>
  </channel>
</rss>

