<description>DNS update using RFC2136 Dynamic protocol.</description>
</rule>
- <rule id="12108" level="0">
+ <rule id="12108" level="5">
<if_sid>12100</if_sid>
<match>query (cache) denied|: query (cache)</match>
<description>Query cache denied (probably config error).</description>
<info type="link">http://www.reedmedia.net/misc/dns/errors.html</info>
+ <group>connection_attempt,</group>
</rule>
<rule id="12109" level="12">
<match>: parsing failed$</match>
<description>Parsing of a configuration file has failed.</description>
</rule>
+
+ <rule id="12149" level="10" frequency="6" timeframe="120">
+ <if_matched_sid>12108</if_matched_sid>
+ <same_source_ip />
+ <description> Multiple query (cache) failures.</description>
+ <group>connection_attempt,</group>
+</rule>
</group> <!-- SYSLOG,NAMED -->