Dnstap Input Plugin


Dnstap logs Graylog input plugin

The plugin provides an input for the Dnstap protocol in Graylog. It can be used to receive data from logs provided by fstrm_capture (e.g. socat FILE:/var/log/unbound/unbound.dnstap TCP:graylog-server:6000 ) or to communicate with DNS server directly (e.g. socat UNIX-LISTEN:/var/run/unbound/dnstap.sock,user=unbound,unlink-early,fork TCP:graylog-server:6000,nodelay,pf=ip4 ).