Re: [Pdns-users] Efficient query logging

2018-04-02 Thread Chris Stradtman
It's not powerdns specific, but we have been using packetbeat for that sort of work. Chris Stradtman On Mon, Apr 2, 2018 at 6:06 AM, Brian Candler wrote: > I'm investigating how to monitor DNS queries as a source of security > information for breach detection. In the case of client machines, w

[Pdns-users] Efficient query logging

2018-04-02 Thread Brian Candler
I'm investigating how to monitor DNS queries as a source of security information for breach detection.  In the case of client machines, we can check the queries against a blacklist of known C&C or malware domains; in the case of servers, we know they should only be making outbound connections t