Richard_22613
Jul 29, 2013Nimbostratus
GTM iRule for DNS_RESPONSE
Hi
Im sure this is something very simple but I'm relatively new to the F5s and cant figure this out.
I'm trying to log DNS requests and replies to a syslog server. The requests work fine, however when I try the following code, I get the error 'line 1: [unknown event (DNS_RESPONSE)] [when DNS_RESPONSE {'
when DNS_RESPONSE {
This rule logs LDNS IP, Geolocation information, the DNS request and DNS Response
Use the HSL option for production environments.
use this line below for lab/test environments where there is no syslog server.
log local0. "LDNS: [IP::remote_addr] - LOCATION: [whereis [IP::remote_addr]] - QUESTION: [DNS::question name], [DNS::question type] - ANSWER: [DNS::answer]"
set hsl [HSL::open -proto UDP -pool hsl_pool]
HSL::send $hsl "<190> LDNS: [IP::remote_addr] - LOCATION: [whereis [IP::remote_addr]] - QUESTION: [DNS::question name], [DNS::question type] - ANSWER: [DNS::answer]"
}
Can anyone point me in the right direction as to why my F5 GTM doesnt like the line when DNS_RESPONSE ? I have a GTM and DNSexpress license.
Thanks
Richard