On Thursday, 25 August 2022 at 11:36:59 UTC+1 [email protected] wrote: > 1) [image: 2022-08-25_20-10-14.png] > > 2) I was checking with tcpdump. Don't know if I'm on pair with your theory > cause client (blackbox) sending syn immediately after receiving "large" udp > packet. >
Does tcpdump decode this "large" udp response? Is it a valid DNS packet? If the resolver switches to TCP immediately - which it is entitled to - this then begs the question of where the 3 second delay is coming from. Again, more tcpdump analysis may be required. -- You received this message because you are subscribed to the Google Groups "Prometheus Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/prometheus-users/14e86df9-e50d-4142-9947-2a56244d00aen%40googlegroups.com.

