--- Begin Message ---
On Tue, 22 Jun 2021 15:56:16 -0700
Randy Bush <[email protected]> wrote:
> >> tcp query flood for cctlds and sec.cctlds, could be others
> >> being sent via popular open servers: goog, neustar, ...
> >> O(100)qps or higher
> >
> > - What was the duration of the event (UTC time start and end)?
>
> after a short break, it is ongoing
>
> > - Any stats on the mix of qnames?
> > * Repeated or distinct?
> > * Extant, NODATA or NXDOMAIN?
>
> i am just running dnstop from cli.
Does your dnstop support TCP? The man page on my machine has the
following mentioned under BUGS:
Does not support TCP at this time.
--
Stefan Ubbink
DNS & Systems Engineer
Present: Mon, Tue, Wed, Fri
SIDN | Meander 501 | 6825 MD | ARNHEM | The Netherlands
T +31 (0)26 352 55 00
https://www.sidn.nl
pgpNo9oaNW1v9.pgp
Description: OpenPGP digital signature
--- End Message ---
_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations