# This configuration sets up DNS traffic monitoring through DNStap on port 6000 and port 6001;
# applies filtering and save to file
#
# As prerequisites, we assume you have 
# - a DNS server which supports DNSTap (unbound, bind, powerdns, etc) for more informations about dnstap, 
#   read the following page: https://dmachard.github.io/posts/0001-dnstap-testing/

# If turned on, debug messages are printed in the standard output
global:
  trace:
    verbose: true

pipelines:
  # Listen on tcp/6000 for incoming DNSTap protobuf messages from dns servers
  # with some transformations to only keep one out of every downsample records
  # and whitelist file which contains:
  # *.google.com$
  # *.github.com$
  - name: tap
    dnstap:
      listen-ip: 0.0.0.0
      listen-port: 6000
    transforms:
      filtering:
        keep-domain-file: ./tests/testsdata/filtering_fqdn.txt
    # Routes DNS messages from the tap collector to standard output
    routing-policy:
      forward: [ console ]

  # Print DNS messages on standard output with TEXT format
  - name: console
    stdout:
      mode: text
