# This configuration sets up DNS traffic monitoring through DNStap on port 6000;
# and applies transformation to reduce qname to lowercase
#
# As prerequisites, we assume you have 
# - a DNS server which supports DNSTap (unbound, bind, powerdns, etc) for more informations about dnstap, 
#   read the following page: https://dmachard.github.io/posts/0001-dnstap-testing/

# If turned on, debug messages are printed in the standard output
global:
  trace:
    verbose: true

pipelines:
  # Listen on tcp/6000 for incoming DNSTap protobuf messages from dns servers
  - name: tap
    dnstap:
      listen-ip: 0.0.0.0
      listen-port: 6000
    # Routes DNS messages from the tap collector to standard output
    routing-policy:
      forward: [ console ]

  # Print DNS messages on standard output with TEXT format
  # with on transformation to reduce qname to lowercase
  # For example: Www.GooGlE.com will be equal to www.google.com
  - name: console
    stdout:
      mode: text
    transforms:
      normalize:
        qname-lowercase: true