dnstap: High speed DNS logging without packet capture

2,086 views · Published 14 February 2014 · 32:56 · Indexed 29 September 2026

Channel: NANOG · 2014 · Science & Technology

Watch on YouTube

Speaker:
Robert Edmonds, Farsight Security, Inc.

The DNS protocol presents interesting logging challenges. Common approaches to DNS logging include instrumentation internal to the DNS server which generates textual log messages ("query logs"), and external passive observation of DNS network traffic ("packet capture"). This presentation will outline some of the strengths and weaknesses of these two approaches and will showcase a hybrid vendor-neutral logging implementation, "dnstap", that can provide at high speed the high quality data needed for DNS monitoring applications such as passive DNS replication and query logging.

More from this channel