Re: DNSSE logging and parsing it

2015-03-05 Thread Daniel Stirnimann
Hi Marco Great question and I'm looking forward to any advice you get. I'm currently using the following regex on our BIND resolvers but they are broken: header => 'DNSSEC error: parent indicates it should be secure', pattern => 'validating \@0x\w+: (.*): got insecure response; parent indicat

DNSSE logging and parsing it

2015-03-05 Thread Marco Davids (SIDN)
Hi, What would be a good way to configure BIND-logging, or rather to filter DNSSEC-validation errors from that logging? Unbound logs stuff like this: Mar 5 12:58:47 xs unbound: [16331:0] info: validation failure : No DNSKEY record from 203.0.113.5 for key example.nl.nl. while building chain o