26–27 Oct 2024
Europe/Prague timezone

Introduction to Vector: DNSTAP processing & lessons learned

27 Oct 2024, 09:35
25m
In-Person Standard Presentation Main Session Session 1

Speaker

Mr John Todd (Quad9)

Description

DNSTAP is used extensively by most open-source DNS components to report on events passing through their query or response phases. Processing DNSTAP messages at large volumes and with highly customizable capabilities is a function of the Vector open-source streaming data processor.

This talk is an introduction and lessons-learned summary of Quad9's implementation of Vector as a DNSTAP processing tool, both at the edge of the network as well as a central "hub" for data from the field.

I will explain some of the fundamentals of the tool, with specific focus on the DNSTAP and protobuf ingestion sources, and will also highlight some of the DNS-specific modules that have been recently incorporated into Vector to permit detailed analysis of DNS data and related enrichments.

Event modification, enrichment, and Prometheus-style aggregation will be covered briefly. The intention of the discussion is to build interest in experimenting with and implementation of this tool, which will build the developer community towards more robust features that are DNS-specific.

What support can we provide to help you deliver your presentation effectively?

Don't make me a timekeeper or chairperson for this session. :-) I'm open to more catchy titles for this talk as well - I'm drawing a blank on something to attract a crowd.

Talk duration 20 Minutes (+5 for Q&A)

Primary author

Mr John Todd (Quad9)

Presentation materials

There are no materials yet.