logo

Tap Into Your Valuable DNS Data

ID: 095e1ba3-262e-53c9-9ba7-e5c231a5faad

STIX ID: report--095e1ba3-262e-53c9-9ba7-e5c231a5faad

Feed Name: Black Hills Infosec Blog

Date Published: 2019-06-03

Date Updated: 2026-04-27

Author: BHIS

...
...

This article is a practical guide to deploying DNSTAP with the ISC BIND DNS server to capture DNS queries and responses efficiently using Google's protocol buffers and the frame-stream (fstrm) tool. It explains required dependencies, building BIND with DNSTAP enabled, configuring fstrm to capture DNSTAP output via a UNIX socket (including a sample systemd service), BIND configuration options for DNSTAP message types, and methods for reading and analyzing the resulting logs with dnstap-read or a custom Python parser.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.