I have created a stream to process incoming bro_dns messages, specifically looking for ‘alien’ address queries.
The stream rules look for
and a regex (.*.)+local
Which should match all queries for something.local , as a simple test
When I run a search using this I see the expected results, but no messages arrive in the stream using exactly the same conditions.
If change the rule processing form ‘both’ to ‘either’, I see all bro_dns messages arrive in the stream.