Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "took" : 6195,
- "timed_out" : false,
- "_shards" : {
- "total" : 5,
- "successful" : 5,
- "failed" : 0
- },
- "hits" : {
- "total" : 3646,
- "max_score" : 3.773673,
- "hits" : [
- {
- "_index" : "packetbeat-2017.01.23",
- "_type" : "dns",
- "_id" : "AVnKo-7k1wOyl1zs31YN",
- "_score" : 3.773673,
- "_source" : {
- "@timestamp" : "2017-01-23T09:24:14.579Z",
- "beat" : {
- "hostname" : "elastic",
- "name" : "elastic",
- "version" : "5.1.2"
- },
- "bytes_out" : 286,
- "client_ip" : "10.100.100.22",
- "client_port" : 29354,
- "client_proc" : "",
- "client_server" : "",
- "dns" : {
- "additionals_count" : 0,
- "answers" : [
- {
- "algorithm" : "RSASHA256",
- "class" : "IN",
- "data" : "keIsOzXcda+/3f00EpJweXDaBJntQQ6lWK6NwaMTgzKjz2DNiZWv+WeFK6zm/Xcq541jv6M2mSEoZeF5gfSbKWn70Ps3yHjgWw2XYosE1j8W3nIprKnXofjyss8Nk4sM7rz7NxThA+iXAwiO0HhYiSLnyvPmpqHN3CFXhPsctZg=",
- "expiration" : "20170202000000",
- "inception" : "20170112000000",
- "key_tag" : "10966",
- "labels" : "2",
- "name" : "2-connect.info.",
- "original_ttl" : "3600",
- "signer_name" : "2-connect.info.",
- "ttl" : "3600",
- "type" : "RRSIG",
- "type_covered" : "MX"
- },
- {
- "class" : "IN",
- "data" : "vs-dc1-as-01.wylance.com.",
- "name" : "2-connect.info.",
- "preference" : 10,
- "ttl" : "3600",
- "type" : "MX"
- },
- {
- "class" : "IN",
- "data" : "vs-dc2-as-01.wylance.com.",
- "name" : "2-connect.info.",
- "preference" : 20,
- "ttl" : "3600",
- "type" : "MX"
- }
- ],
- "answers_count" : 3,
- "authorities_count" : 0,
- "flags" : {
- "authentic_data" : false,
- "authoritative" : true,
- "checking_disabled" : false,
- "recursion_available" : false,
- "recursion_desired" : false,
- "truncated_response" : false
- },
- "id" : 40285,
- "op_code" : "QUERY",
- "opt" : {
- "do" : true,
- "ext_rcode" : "Unknown 15",
- "udp_size" : 1680,
- "version" : "0"
- },
- "question" : {
- "class" : "IN",
- "etld_plus_one" : "2-connect.info.",
- "name" : "2-connect.info.",
- "type" : "MX"
- },
- "response_code" : "NOERROR"
- },
- "ip" : "217.194.122.34",
- "method" : "QUERY",
- "notes" : "Response: received without an associated Query",
- "port" : 53,
- "proc" : "",
- "query" : "class IN, type MX, 2-connect.info.",
- "resource" : "2-connect.info.",
- "server" : "",
- "status" : "Error",
- "transport" : "udp",
- "type" : "dns"
- }
- },
- {
- "_index" : "packetbeat-2017.01.23",
- "_type" : "dns",
- "_id" : "AVnKo-7k1wOyl1zs31YT",
- "_score" : 3.76386,
- "_source" : {
- "@timestamp" : "2017-01-23T09:24:14.587Z",
- "beat" : {
- "hostname" : "elastic",
- "name" : "elastic",
- "version" : "5.1.2"
- },
- "bytes_out" : 817,
- "client_ip" : "10.100.100.22",
- "client_port" : 14048,
- "client_proc" : "",
- "client_server" : "",
- "dns" : {
- "additionals" : [
- {
- "class" : "IN",
- "data" : "199.254.31.1",
- "name" : "a0.info.afilias-nst.info.",
- "ttl" : "172800",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "199.249.113.1",
- "name" : "a2.info.afilias-nst.info.",
- "ttl" : "172800",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "199.254.48.1",
- "name" : "b0.info.afilias-nst.org.",
- "ttl" : "172800",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "199.249.121.1",
- "name" : "b2.info.afilias-nst.org.",
- "ttl" : "172800",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "199.254.49.1",
- "name" : "c0.info.afilias-nst.info.",
- "ttl" : "172800",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "199.254.50.1",
- "name" : "d0.info.afilias-nst.org.",
- "ttl" : "172800",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "2001:500:19::1",
- "name" : "a0.info.afilias-nst.info.",
- "ttl" : "172800",
- "type" : "AAAA"
- },
- {
- "class" : "IN",
- "data" : "2001:500:41::1",
- "name" : "a2.info.afilias-nst.info.",
- "ttl" : "172800",
- "type" : "AAAA"
- },
- {
- "class" : "IN",
- "data" : "2001:500:1a::1",
- "name" : "b0.info.afilias-nst.org.",
- "ttl" : "172800",
- "type" : "AAAA"
- },
- {
- "class" : "IN",
- "data" : "2001:500:49::1",
- "name" : "b2.info.afilias-nst.org.",
- "ttl" : "172800",
- "type" : "AAAA"
- },
- {
- "class" : "IN",
- "data" : "2001:500:1b::1",
- "name" : "c0.info.afilias-nst.info.",
- "ttl" : "172800",
- "type" : "AAAA"
- },
- {
- "class" : "IN",
- "data" : "2001:500:1c::1",
- "name" : "d0.info.afilias-nst.org.",
- "ttl" : "172800",
- "type" : "AAAA"
- }
- ],
- "additionals_count" : 12,
- "answers_count" : 0,
- "authorities" : [
- {
- "class" : "IN",
- "data" : "a0.info.afilias-nst.info.",
- "name" : "info.",
- "ttl" : "172800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "a2.info.afilias-nst.info.",
- "name" : "info.",
- "ttl" : "172800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "b0.info.afilias-nst.org.",
- "name" : "info.",
- "ttl" : "172800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "b2.info.afilias-nst.org.",
- "name" : "info.",
- "ttl" : "172800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "c0.info.afilias-nst.info.",
- "name" : "info.",
- "ttl" : "172800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "d0.info.afilias-nst.org.",
- "name" : "info.",
- "ttl" : "172800",
- "type" : "NS"
- },
- {
- "algorithm" : "RSASHA1-NSEC3-SHA1",
- "class" : "IN",
- "data" : "197789A2CBABA6FECD0B5AC88C5BC414CE1FC309",
- "digest_type" : "SHA1",
- "key_tag" : "8674",
- "name" : "info.",
- "ttl" : "86400",
- "type" : "DS"
- },
- {
- "algorithm" : "RSASHA1-NSEC3-SHA1",
- "class" : "IN",
- "data" : "EC9B6082B96B5F87143696F2B483ACC9B2C433DCE0C94E70F1FF5648CA18008B",
- "digest_type" : "SHA256",
- "key_tag" : "8674",
- "name" : "info.",
- "ttl" : "86400",
- "type" : "DS"
- },
- {
- "algorithm" : "RSASHA256",
- "class" : "IN",
- "data" : "QECD+rcR5O5v3TDWNCiKamKuhiqP1DIN95TeGNvlFuoygaOWByCwwIVrhUUhkOYaflzkIV+vVw6b9jsvsgSjdbWTDjj9zClnAKevPhAO11ukVdv6x6pj8qVIoiATZmVf9dk+LcsDWncUZ4/57JHw7J+VPG15JJbAjsdvL9W/W0tG0XCCpsASbV6Y0K1GdPIZnbcYkYEoKanOSfldSfSGpxFrRTe3rCH9mta8BzWLAditwwZ156Le21o9IgyIzt4rn9lCNgx9bTQL7ipf95iVVyhqMlxDgSgSbucezYayyM7eUkBhwypzsMWQqrJuKp5AyA2VIJRAw9DqMgIAtwgDfg==",
- "expiration" : "20170205050000",
- "inception" : "20170123040000",
- "key_tag" : "61045",
- "labels" : "1",
- "name" : "info.",
- "original_ttl" : "86400",
- "signer_name" : ".",
- "ttl" : "86400",
- "type" : "RRSIG",
- "type_covered" : "DS"
- }
- ],
- "authorities_count" : 9,
- "flags" : {
- "authentic_data" : false,
- "authoritative" : false,
- "checking_disabled" : false,
- "recursion_available" : false,
- "recursion_desired" : false,
- "truncated_response" : false
- },
- "id" : 55662,
- "op_code" : "QUERY",
- "opt" : {
- "do" : true,
- "ext_rcode" : "Unknown 15",
- "udp_size" : 4096,
- "version" : "0"
- },
- "question" : {
- "class" : "IN",
- "etld_plus_one" : "2-connect.info.",
- "name" : "2-connect.info.",
- "type" : "DS"
- },
- "response_code" : "NOERROR"
- },
- "ip" : "199.7.83.42",
- "method" : "QUERY",
- "notes" : "Response: received without an associated Query",
- "port" : 53,
- "proc" : "",
- "query" : "class IN, type DS, 2-connect.info.",
- "resource" : "2-connect.info.",
- "server" : "",
- "status" : "Error",
- "transport" : "udp",
- "type" : "dns"
- }
- },
- {
- "_index" : "packetbeat-2017.01.23",
- "_type" : "dns",
- "_id" : "AVnKW9fhrkcgPvjzna63",
- "_score" : 2.8510847,
- "_source" : {
- "@timestamp" : "2017-01-23T08:01:57.944Z",
- "beat" : {
- "hostname" : "elastic",
- "name" : "elastic",
- "version" : "5.1.2"
- },
- "bytes_out" : 254,
- "client_ip" : "10.100.100.22",
- "client_port" : 18897,
- "client_proc" : "",
- "client_server" : "",
- "dns" : {
- "additionals_count" : 0,
- "answers" : [
- {
- "class" : "IN",
- "data" : "52.42.22.188",
- "name" : "phototalk-api-adr-1610511466.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "54.69.8.53",
- "name" : "phototalk-api-adr-1610511466.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- }
- ],
- "answers_count" : 2,
- "authorities" : [
- {
- "class" : "IN",
- "data" : "ns-1475.awsdns-56.org.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-1769.awsdns-29.co.uk.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-332.awsdns-41.com.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-560.awsdns-06.net.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- }
- ],
- "authorities_count" : 4,
- "flags" : {
- "authentic_data" : false,
- "authoritative" : true,
- "checking_disabled" : false,
- "recursion_available" : false,
- "recursion_desired" : false,
- "truncated_response" : false
- },
- "id" : 60185,
- "op_code" : "QUERY",
- "opt" : {
- "do" : false,
- "ext_rcode" : "Unknown 15",
- "udp_size" : 4096,
- "version" : "0"
- },
- "question" : {
- "class" : "IN",
- "etld_plus_one" : "us-west-2.elb.amazonaws.com.",
- "name" : "phototalk-api-adr-1610511466.us-west-2.elb.amazonaws.com.",
- "type" : "A"
- },
- "response_code" : "NOERROR"
- },
- "ip" : "205.251.194.48",
- "method" : "QUERY",
- "notes" : "Response: received without an associated Query",
- "port" : 53,
- "proc" : "",
- "query" : "class IN, type A, phototalk-api-adr-1610511466.us-west-2.elb.amazonaws.com.",
- "resource" : "phototalk-api-adr-1610511466.us-west-2.elb.amazonaws.com.",
- "server" : "",
- "status" : "Error",
- "transport" : "udp",
- "type" : "dns"
- }
- },
- {
- "_index" : "packetbeat-2017.01.23",
- "_type" : "dns",
- "_id" : "AVnKXhDArkcgPvjznxdm",
- "_score" : 2.8510847,
- "_source" : {
- "@timestamp" : "2017-01-23T08:05:39.330Z",
- "beat" : {
- "hostname" : "elastic",
- "name" : "elastic",
- "version" : "5.1.2"
- },
- "bytes_out" : 237,
- "client_ip" : "10.100.100.21",
- "client_port" : 41770,
- "client_proc" : "",
- "client_server" : "",
- "dns" : {
- "additionals_count" : 0,
- "answers" : [
- {
- "class" : "IN",
- "data" : "52.39.28.209",
- "name" : "prod-dep-lb-1273907130.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "54.213.109.212",
- "name" : "prod-dep-lb-1273907130.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- }
- ],
- "answers_count" : 2,
- "authorities" : [
- {
- "class" : "IN",
- "data" : "ns-1475.awsdns-56.org.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-1769.awsdns-29.co.uk.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-332.awsdns-41.com.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-560.awsdns-06.net.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- }
- ],
- "authorities_count" : 4,
- "flags" : {
- "authentic_data" : false,
- "authoritative" : true,
- "checking_disabled" : false,
- "recursion_available" : false,
- "recursion_desired" : false,
- "truncated_response" : false
- },
- "id" : 45962,
- "op_code" : "QUERY",
- "question" : {
- "class" : "IN",
- "etld_plus_one" : "us-west-2.elb.amazonaws.com.",
- "name" : "prod-dep-lb-1273907130.us-west-2.elb.amazonaws.com.",
- "type" : "A"
- },
- "response_code" : "NOERROR"
- },
- "ip" : "205.251.194.48",
- "method" : "QUERY",
- "notes" : "Response: received without an associated Query",
- "port" : 53,
- "proc" : "",
- "query" : "class IN, type A, prod-dep-lb-1273907130.us-west-2.elb.amazonaws.com.",
- "resource" : "prod-dep-lb-1273907130.us-west-2.elb.amazonaws.com.",
- "server" : "",
- "status" : "Error",
- "transport" : "udp",
- "type" : "dns"
- }
- },
- {
- "_index" : "packetbeat-2017.01.23",
- "_type" : "dns",
- "_id" : "AVnKaDd_rkcgPvjzpp3S",
- "_score" : 2.8510847,
- "_source" : {
- "@timestamp" : "2017-01-23T08:15:09.856Z",
- "beat" : {
- "hostname" : "elastic",
- "name" : "elastic",
- "version" : "5.1.2"
- },
- "bytes_out" : 350,
- "client_ip" : "10.100.100.23",
- "client_port" : 14182,
- "client_proc" : "",
- "client_server" : "",
- "dns" : {
- "additionals_count" : 0,
- "answers" : [
- {
- "class" : "IN",
- "data" : "52.26.60.195",
- "name" : "pubster-production-519352041.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.39.214.89",
- "name" : "pubster-production-519352041.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.35.164.51",
- "name" : "pubster-production-519352041.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "54.200.59.241",
- "name" : "pubster-production-519352041.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.27.172.142",
- "name" : "pubster-production-519352041.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "54.70.5.173",
- "name" : "pubster-production-519352041.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.27.30.98",
- "name" : "pubster-production-519352041.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.26.39.140",
- "name" : "pubster-production-519352041.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- }
- ],
- "answers_count" : 8,
- "authorities" : [
- {
- "class" : "IN",
- "data" : "ns-1475.awsdns-56.org.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-1769.awsdns-29.co.uk.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-332.awsdns-41.com.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-560.awsdns-06.net.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- }
- ],
- "authorities_count" : 4,
- "flags" : {
- "authentic_data" : false,
- "authoritative" : true,
- "checking_disabled" : false,
- "recursion_available" : false,
- "recursion_desired" : false,
- "truncated_response" : false
- },
- "id" : 2799,
- "op_code" : "QUERY",
- "opt" : {
- "do" : false,
- "ext_rcode" : "Unknown 15",
- "udp_size" : 4096,
- "version" : "0"
- },
- "question" : {
- "class" : "IN",
- "etld_plus_one" : "us-west-2.elb.amazonaws.com.",
- "name" : "pubster-production-519352041.us-west-2.elb.amazonaws.com.",
- "type" : "A"
- },
- "response_code" : "NOERROR"
- },
- "ip" : "205.251.194.48",
- "method" : "QUERY",
- "notes" : "Response: received without an associated Query",
- "port" : 53,
- "proc" : "",
- "query" : "class IN, type A, pubster-production-519352041.us-west-2.elb.amazonaws.com.",
- "resource" : "pubster-production-519352041.us-west-2.elb.amazonaws.com.",
- "server" : "",
- "status" : "Error",
- "transport" : "udp",
- "type" : "dns"
- }
- },
- {
- "_index" : "packetbeat-2017.01.23",
- "_type" : "dns",
- "_id" : "AVnKaEjbrkcgPvjzpqNL",
- "_score" : 2.8510847,
- "_source" : {
- "@timestamp" : "2017-01-23T08:19:03.162Z",
- "beat" : {
- "hostname" : "elastic",
- "name" : "elastic",
- "version" : "5.1.2"
- },
- "bytes_out" : 159,
- "client_ip" : "10.100.100.21",
- "client_port" : 49385,
- "client_proc" : "",
- "client_server" : "",
- "dns" : {
- "additionals_count" : 0,
- "answers_count" : 0,
- "authorities" : [
- {
- "class" : "IN",
- "data" : "ns-332.awsdns-41.com.",
- "expire" : 1209600,
- "minimum" : 60,
- "name" : "us-west-2.elb.amazonaws.com.",
- "refresh" : 7200,
- "retry" : 900,
- "rname" : "awsdns-hostmaster.amazon.com.",
- "serial" : 1,
- "ttl" : "60",
- "type" : "SOA"
- }
- ],
- "authorities_count" : 1,
- "flags" : {
- "authentic_data" : false,
- "authoritative" : true,
- "checking_disabled" : false,
- "recursion_available" : false,
- "recursion_desired" : false,
- "truncated_response" : false
- },
- "id" : 14353,
- "op_code" : "QUERY",
- "question" : {
- "class" : "IN",
- "etld_plus_one" : "us-west-2.elb.amazonaws.com.",
- "name" : "shield-normandy-elb-prod-2099053585.us-west-2.elb.amazonaws.com.",
- "type" : "AAAA"
- },
- "response_code" : "NOERROR"
- },
- "ip" : "205.251.194.48",
- "method" : "QUERY",
- "notes" : "Response: received without an associated Query",
- "port" : 53,
- "proc" : "",
- "query" : "class IN, type AAAA, shield-normandy-elb-prod-2099053585.us-west-2.elb.amazonaws.com.",
- "resource" : "shield-normandy-elb-prod-2099053585.us-west-2.elb.amazonaws.com.",
- "server" : "",
- "status" : "Error",
- "transport" : "udp",
- "type" : "dns"
- }
- },
- {
- "_index" : "packetbeat-2017.01.23",
- "_type" : "dns",
- "_id" : "AVnKcmMCrkcgPvjzraYk",
- "_score" : 2.8510847,
- "_source" : {
- "@timestamp" : "2017-01-23T08:30:10.440Z",
- "beat" : {
- "hostname" : "elastic",
- "name" : "elastic",
- "version" : "5.1.2"
- },
- "bytes_out" : 316,
- "client_ip" : "10.100.100.21",
- "client_port" : 46464,
- "client_proc" : "",
- "client_server" : "",
- "dns" : {
- "additionals_count" : 0,
- "answers" : [
- {
- "class" : "IN",
- "data" : "52.10.67.30",
- "name" : "PRD-ONTV-OPENAPI-ELB-Oregon-337487521.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.42.242.20",
- "name" : "PRD-ONTV-OPENAPI-ELB-Oregon-337487521.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.26.43.241",
- "name" : "PRD-ONTV-OPENAPI-ELB-Oregon-337487521.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.42.159.189",
- "name" : "PRD-ONTV-OPENAPI-ELB-Oregon-337487521.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.88.241.72",
- "name" : "PRD-ONTV-OPENAPI-ELB-Oregon-337487521.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.89.229.99",
- "name" : "PRD-ONTV-OPENAPI-ELB-Oregon-337487521.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- }
- ],
- "answers_count" : 6,
- "authorities" : [
- {
- "class" : "IN",
- "data" : "ns-1475.awsdns-56.org.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-1769.awsdns-29.co.uk.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-332.awsdns-41.com.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-560.awsdns-06.net.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- }
- ],
- "authorities_count" : 4,
- "flags" : {
- "authentic_data" : false,
- "authoritative" : true,
- "checking_disabled" : false,
- "recursion_available" : false,
- "recursion_desired" : false,
- "truncated_response" : false
- },
- "id" : 37460,
- "op_code" : "QUERY",
- "question" : {
- "class" : "IN",
- "etld_plus_one" : "us-west-2.elb.amazonaws.com.",
- "name" : "PRD-ONTV-OPENAPI-ELB-Oregon-337487521.us-west-2.elb.amazonaws.com.",
- "type" : "A"
- },
- "response_code" : "NOERROR"
- },
- "ip" : "205.251.194.48",
- "method" : "QUERY",
- "notes" : "Response: received without an associated Query",
- "port" : 53,
- "proc" : "",
- "query" : "class IN, type A, PRD-ONTV-OPENAPI-ELB-Oregon-337487521.us-west-2.elb.amazonaws.com.",
- "resource" : "PRD-ONTV-OPENAPI-ELB-Oregon-337487521.us-west-2.elb.amazonaws.com.",
- "server" : "",
- "status" : "Error",
- "transport" : "udp",
- "type" : "dns"
- }
- },
- {
- "_index" : "packetbeat-2017.01.23",
- "_type" : "dns",
- "_id" : "AVnKdPpqrkcgPvjzrzKx",
- "_score" : 2.8510847,
- "_source" : {
- "@timestamp" : "2017-01-23T08:32:59.320Z",
- "beat" : {
- "hostname" : "elastic",
- "name" : "elastic",
- "version" : "5.1.2"
- },
- "bytes_out" : 341,
- "client_ip" : "10.100.100.21",
- "client_port" : 47354,
- "client_proc" : "",
- "client_server" : "",
- "dns" : {
- "additionals_count" : 0,
- "answers" : [
- {
- "class" : "IN",
- "data" : "52.35.142.235",
- "name" : "aws-p-or-tag-elb-01-2063342728.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.25.154.73",
- "name" : "aws-p-or-tag-elb-01-2063342728.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.24.203.21",
- "name" : "aws-p-or-tag-elb-01-2063342728.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.36.136.240",
- "name" : "aws-p-or-tag-elb-01-2063342728.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.33.58.61",
- "name" : "aws-p-or-tag-elb-01-2063342728.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.35.216.42",
- "name" : "aws-p-or-tag-elb-01-2063342728.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.35.233.55",
- "name" : "aws-p-or-tag-elb-01-2063342728.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.11.193.255",
- "name" : "aws-p-or-tag-elb-01-2063342728.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- }
- ],
- "answers_count" : 8,
- "authorities" : [
- {
- "class" : "IN",
- "data" : "ns-1475.awsdns-56.org.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-1769.awsdns-29.co.uk.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-332.awsdns-41.com.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-560.awsdns-06.net.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- }
- ],
- "authorities_count" : 4,
- "flags" : {
- "authentic_data" : false,
- "authoritative" : true,
- "checking_disabled" : false,
- "recursion_available" : false,
- "recursion_desired" : false,
- "truncated_response" : false
- },
- "id" : 7400,
- "op_code" : "QUERY",
- "question" : {
- "class" : "IN",
- "etld_plus_one" : "us-west-2.elb.amazonaws.com.",
- "name" : "aws-p-or-tag-elb-01-2063342728.us-west-2.elb.amazonaws.com.",
- "type" : "A"
- },
- "response_code" : "NOERROR"
- },
- "ip" : "205.251.197.195",
- "method" : "QUERY",
- "notes" : "Response: received without an associated Query",
- "port" : 53,
- "proc" : "",
- "query" : "class IN, type A, aws-p-or-tag-elb-01-2063342728.us-west-2.elb.amazonaws.com.",
- "resource" : "aws-p-or-tag-elb-01-2063342728.us-west-2.elb.amazonaws.com.",
- "server" : "",
- "status" : "Error",
- "transport" : "udp",
- "type" : "dns"
- }
- },
- {
- "_index" : "packetbeat-2017.01.23",
- "_type" : "dns",
- "_id" : "AVnKdPpqrkcgPvjzrzLF",
- "_score" : 2.8510847,
- "_source" : {
- "@timestamp" : "2017-01-23T08:32:59.363Z",
- "beat" : {
- "hostname" : "elastic",
- "name" : "elastic",
- "version" : "5.1.2"
- },
- "bytes_out" : 256,
- "client_ip" : "10.100.100.22",
- "client_port" : 14167,
- "client_proc" : "",
- "client_server" : "",
- "dns" : {
- "additionals_count" : 0,
- "answers" : [
- {
- "class" : "IN",
- "data" : "52.40.47.184",
- "name" : "PRD-GAME-V1-API-WAS-1347751974.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.25.241.68",
- "name" : "PRD-GAME-V1-API-WAS-1347751974.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- }
- ],
- "answers_count" : 2,
- "authorities" : [
- {
- "class" : "IN",
- "data" : "ns-1475.awsdns-56.org.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-1769.awsdns-29.co.uk.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-332.awsdns-41.com.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-560.awsdns-06.net.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- }
- ],
- "authorities_count" : 4,
- "flags" : {
- "authentic_data" : false,
- "authoritative" : true,
- "checking_disabled" : false,
- "recursion_available" : false,
- "recursion_desired" : false,
- "truncated_response" : false
- },
- "id" : 33778,
- "op_code" : "QUERY",
- "opt" : {
- "do" : false,
- "ext_rcode" : "Unknown 15",
- "udp_size" : 4096,
- "version" : "0"
- },
- "question" : {
- "class" : "IN",
- "etld_plus_one" : "us-west-2.elb.amazonaws.com.",
- "name" : "PRD-GAME-V1-API-WAS-1347751974.us-west-2.elb.amazonaws.com.",
- "type" : "A"
- },
- "response_code" : "NOERROR"
- },
- "ip" : "205.251.194.48",
- "method" : "QUERY",
- "notes" : "Response: received without an associated Query",
- "port" : 53,
- "proc" : "",
- "query" : "class IN, type A, PRD-GAME-V1-API-WAS-1347751974.us-west-2.elb.amazonaws.com.",
- "resource" : "PRD-GAME-V1-API-WAS-1347751974.us-west-2.elb.amazonaws.com.",
- "server" : "",
- "status" : "Error",
- "transport" : "udp",
- "type" : "dns"
- }
- },
- {
- "_index" : "packetbeat-2017.01.23",
- "_type" : "dns",
- "_id" : "AVnKcoUJrkcgPvjzrbQ5",
- "_score" : 2.8510847,
- "_source" : {
- "@timestamp" : "2017-01-23T08:30:15.682Z",
- "beat" : {
- "hostname" : "elastic",
- "name" : "elastic",
- "version" : "5.1.2"
- },
- "bytes_out" : 345,
- "client_ip" : "10.100.100.21",
- "client_port" : 41616,
- "client_proc" : "",
- "client_server" : "",
- "dns" : {
- "additionals_count" : 0,
- "answers" : [
- {
- "class" : "IN",
- "data" : "54.200.95.137",
- "name" : "elb001-asm-edge01-np-01-1168821478.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "50.112.184.199",
- "name" : "elb001-asm-edge01-np-01-1168821478.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.10.166.97",
- "name" : "elb001-asm-edge01-np-01-1168821478.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.26.252.243",
- "name" : "elb001-asm-edge01-np-01-1168821478.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.10.40.28",
- "name" : "elb001-asm-edge01-np-01-1168821478.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.25.114.255",
- "name" : "elb001-asm-edge01-np-01-1168821478.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "52.10.142.227",
- "name" : "elb001-asm-edge01-np-01-1168821478.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- },
- {
- "class" : "IN",
- "data" : "50.112.168.203",
- "name" : "elb001-asm-edge01-np-01-1168821478.us-west-2.elb.amazonaws.com.",
- "ttl" : "60",
- "type" : "A"
- }
- ],
- "answers_count" : 8,
- "authorities" : [
- {
- "class" : "IN",
- "data" : "ns-1475.awsdns-56.org.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-1769.awsdns-29.co.uk.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-332.awsdns-41.com.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- },
- {
- "class" : "IN",
- "data" : "ns-560.awsdns-06.net.",
- "name" : "us-west-2.elb.amazonaws.com.",
- "ttl" : "1800",
- "type" : "NS"
- }
- ],
- "authorities_count" : 4,
- "flags" : {
- "authentic_data" : false,
- "authoritative" : true,
- "checking_disabled" : false,
- "recursion_available" : false,
- "recursion_desired" : false,
- "truncated_response" : false
- },
- "id" : 36011,
- "op_code" : "QUERY",
- "question" : {
- "class" : "IN",
- "etld_plus_one" : "us-west-2.elb.amazonaws.com.",
- "name" : "elb001-asm-edge01-np-01-1168821478.us-west-2.elb.amazonaws.com.",
- "type" : "A"
- },
- "response_code" : "NOERROR"
- },
- "ip" : "205.251.194.48",
- "method" : "QUERY",
- "notes" : "Response: received without an associated Query",
- "port" : 53,
- "proc" : "",
- "query" : "class IN, type A, elb001-asm-edge01-np-01-1168821478.us-west-2.elb.amazonaws.com.",
- "resource" : "elb001-asm-edge01-np-01-1168821478.us-west-2.elb.amazonaws.com.",
- "server" : "",
- "status" : "Error",
- "transport" : "udp",
- "type" : "dns"
- }
- }
- ]
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment