Skip to main content

DNS

How DNS protocol is metered.

File Location

/usr/local/etc/trisul-probe/domain0/probe0/context0/PI-CCCBBBB3-125E-48D0-8AC9-A7E3AD2F60FD.xml

<TrisulPluginConfiguration>
<Policy>
<description>Controls how DNS extraction works </description>
<SampleRate>1</SampleRate>
<CreateFTSDocument>false</CreateFTSDocument>
<ExtractResources>true</ExtractResources>
<MergeCDN>true</MergeCDN>
<TrackBaseDomains>true</TrackBaseDomains>
<BloomFilterResetMask>2097151</BloomFilterResetMask>
<GenerateAlertOnError>true</GenerateAlertOnError>
</Policy>
</TrisulPluginConfiguration>

Policy

ParametersDefaultsDescription
DescriptionControls how DNS extraction works
SampleRate1Once every X packets
CreateFTSDocumenttrueDo you want to create a Full Text Search Document.
ExtractResourcestrueExtract DNS Resources. Resources can be thought of as Logs
MergeCDNtrueIf true, CDN names like akamai.. in answer records map to the original Query name
TrackBaseDomainstrueEnable base domains feature.
BloomFilterResetMask20971512^21-1 increase this if you have a very large number of DNS responses
GenerateAlertOnErrortrueNXDomain responses will result in a UserAlerts error