1 **Phase 1: Completed pre-decoding.
2 full event: 'Apr 17 22:20:29 hostj named[312]: [ID 295310 daemon.notice] security: notice: dropping source port zero packet from [64.211.251.254].0'
5 log: 'security: notice: dropping source port zero packet from [64.211.251.254].0'
7 **Phase 2: Completed decoding.
9 srcip: '64.211.251.254'
11 **Phase 3: Completed filtering (rules).
14 Description: 'Invalid DNS packet. Possibility of attack.'
15 **Alert to be generated.