1 Transform rm_client_from_dns_resp {
2 Match (dns_resp=1, client) Replace (dns_resp=1);
5 Pdu dns_pdu Proto dns Transport ip {
6 Extract addr From ip.addr;
7 Extract dns_id From dns.id;
8 Extract dns_resp From dns.flags.response;
9 Extract host From dns.qry.name;
10 Extract client From ip.src;
11 Transform rm_client_from_dns_resp;
14 Gop dns_req On dns_pdu Match (addr,addr,dns_id) {
20 Transform rm_client_from_http_resp1 {
22 Match Every (addr) Insert (not_rq);
25 Transform rm_client_from_http_resp2 {
26 Match (not_rq, client) Replace ();
29 Pdu http_pdu Proto http Transport tcp/ip {
30 Extract addr From ip.addr;
31 Extract port From tcp.port;
32 Extract http_rq From http.request.method;
33 Extract http_rs From http.response;
34 Extract host From http.host;
35 Extract client From ip.src;
36 Transform rm_client_from_http_resp1, rm_client_from_http_resp2;
40 Gop http_req On http_pdu Match (addr, addr, port, port) {
47 Member http_req (host, client);
48 Member dns_req (host, client);