--- Begin Message ---
On Tue, 22 Jun 2021 15:56:16 -0700
Randy Bush <[email protected]> wrote:

> >> tcp query flood for cctlds and sec.cctlds, could be others
> >> being sent via popular open servers: goog, neustar, ...
> >> O(100)qps or higher  
> > 
> > - What was the duration of the event (UTC time start and end)?  
> 
> after a short break, it is ongoing
> 
> > - Any stats on the mix of qnames?
> >     * Repeated or distinct?
> >     * Extant, NODATA or NXDOMAIN?  
> 
> i am just running dnstop from cli.

Does your dnstop support TCP? The man page on my machine has the
following mentioned under BUGS:

Does not support TCP at this time.


-- 
Stefan Ubbink
DNS & Systems Engineer
Present: Mon, Tue, Wed, Fri
SIDN | Meander 501 | 6825 MD | ARNHEM | The Netherlands
T +31 (0)26 352 55 00
https://www.sidn.nl

Attachment: pgpNo9oaNW1v9.pgp
Description: OpenPGP digital signature


--- End Message ---
_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations

Reply via email to