DNS-collector is a free, open source networking & connectivity project written in Go and released under MIT. It has 570 GitHub stars, 89 forks and 2 open issues, and was last pushed 6 days ago. On this registry it ranks #61 of 61 tracked projects in Networking & Connectivity, with 5 head-to-head comparisons available.

What is DNS-collector?

DNS-collector is a lightweight, open-source DNS telemetry pipeline in Go that captures queries and responses from DNS servers and forwards normalized, enriched events to monitoring, analytics, and security systems.

What it is

DNS-collector is a Go program that sits between your DNS infrastructure and your data stack. It ingests DNS traffic through the high-speed DNStap protocol or live wire packet capture, filters and normalizes the records at wire speed, enriches them on the fly, and dispatches batched events onward to destinations such as ClickHouse, Kafka, Loki, Elasticsearch, Syslog, and Prometheus. It is configured through a config.yml pipeline definition, where each named pipeline combines a collector, a set of transforms, and a routing policy to one or more loggers.

The problem it addresses is that DNS servers emit telemetry that is noisy and difficult to place directly into a SIEM or observability stack. DNS-collector discards noise such as health checks, internal probes, and spam before it reaches storage, decorates records with GeoIP, ASN, threat intelligence, metadata, and custom tags, and understands DNS specifics including EDNS, query types, and latency tracking, while also being able to anonymize user IPs before storage.

Key capabilities

  • Ingests streams from BIND, PowerDNS, Unbound, and CoreDNS via the DNStap protocol or live wire packet capture.
  • Filters out health checks, internal probes, and spam at wire speed before the data reaches storage.
  • Enriches records on the fly with GeoIP, ASN, threat intelligence, metadata, and custom tags.
  • Dispatches batched events to ClickHouse, Kafka, Loki, Elasticsearch, Syslog, Prometheus, and other destinations.
  • Writes output in multiple formats, including text, JSON, PCAP, and Jinja2 templates.
  • Extends DNStap with TLS encryption, compression, and additional metadata capabilities.
  • Exposes a REST API and Prometheus metrics for telemetry, alongside performance tuning guidance.

Who uses it and how

  • Operators running homelab DNS servers who want a single pipeline from a DNStap listener on tcp/6000 through to stdout or a log file.
  • Enterprise teams running BIND, PowerDNS, or Unbound who need high-performance DNS telemetry with a lightweight footprint at any scale of DNS infrastructure.
  • Security teams forwarding DNS events into a SIEM or Loki for anomaly detection, with sensitive fields such as user IPs anonymized before storage.
  • Observability engineers wiring DNS metrics into Grafana and Prometheus for latency tracking and dashboarding.
  • Operators who discard noisy health-check and probe traffic upstream so that only meaningful events reach ClickHouse, Kafka, or Elasticsearch.

Getting started

Download the latest release from GitHub, create a config.yml pipeline that listens for DNStap on 0.0.0.0:6000 and routes to console, then run ./dnscollector -config config.yml. A Docker image is published as go-dnscollector on Docker Hub, with container deployment documented separately.

How it compares

DNS-collector fits among the DNS servers and ingestion tools it integrates with rather than replacing them: it is the collector layer for BIND, PowerDNS, Unbound, and CoreDNS, and the delivery layer toward Kafka, Loki, Elasticsearch, and Prometheus. The related projects DNS-tester and CoreDNS-GSLB cover DNS load testing and GSLB functionality respectively, leaving DNS-collector to handle the capture, filtering, and forwarding of DNS telemetry.

When to use it — and when not

Because it is self-hosted, you must operate the collector itself, its config.yml pipeline, and whatever downstream storage and output systems you route events to, plus any DNStap configuration on your DNS servers. It is a poor fit if you only need a one-off look at DNS traffic rather than a continuously running pipeline, or if you want DNS telemetry without running a Go service. The repository is MIT-licensed with only 2 open issues, but test coverage sits at 67 percent, so edge cases in less common collector and logger combinations may be less well exercised.

project readme (upstream, from github) — read inline

DNS-collector

release docker Go version Go tests Go coverage Go bench

What is DNS-collector?

DNS-collector is a lightweight tool that captures DNS queries and responses from your DNS servers, processes them intelligently, and sends clean data to your monitoring, analytics and security systems.

What it does:

  • Captures at scale: Ingests streams from BIND, PowerDNS, Unbound, etc., via high-speed DNStap protocol or live wire packet capture.
  • Filters & normalizes: Discards noise (health checks, internal probes, spam) at wire speed before reaching storage.
  • Enriches on-the-fly: Decorates records with GeoIP, ASN, threat intelligence, metadata, and custom tags.
  • Streams everywhere: Dispatches batched events to ClickHouse, Kafka, Loki, Elasticsearch, Syslog, Prometheus, and more.

Why DNS-collector?

The missing high-performance data collector between DNS servers and your SIEM/observability/analytics stack.

  • From Homelabs to Enterprises: High-performance DNS telemetry pipeline with a lightweight footprint for any scale of DNS infrastructure (BIND, PowerDNS, Unbound, etc.)
  • DNS-Native & Edge Processing: Understands EDNS, query types, latency tracking, and anonymizes user IPs before storage.
  • Flexible outputs: Files, syslog, databases, monitoring tools and more...
  • Production ready: Used in real networks, tested with major DNS servers
  • Enhanced DNStap: TLS encryption, compression, and more metadata capabilities

🚀 Quick Start

Download the latest release and create a simple config.yml pipeline:

pipelines:
  - name: tap
    dnstap:
      listen-ip: 0.0.0.0
      listen-port: 6000
    transforms:
      normalize:
        qname-lowercase: true
    routing-policy:
      forward: [ console ]
  - name: console
    stdout:
      mode: text

Default setup listens on tcp/6000 for DNStap streams and outputs to stdout.

Run the collector:

./dnscollector -config config.yml

run

📚 Documentation

Topic Description
📝 Formats Supported output formats (text, JSON, PCAP, Jinja2, etc.)
🔧 Configuration Complete config reference
📥 Collectors Input sources (network packet sniffer, DNStap server, etc.)
📤 Loggers Output destinations (Kafka, Prometheus, syslog, Loki, etc.)
🔄 Transformers Data enrichment options
🐳 Docker Container deployment
🔍 Examples Ready-to-use configs
🔗 Sources & Sinks Integration with popular tools and DNS servers
⭐ Enhanced DNStap Enhanced DNSTap features
📊 Telemetry REST API and Prometheus metrics
⚡ Performance Tuning Performance tuning guide

👥 Contributions

Contributions are welcome! Check out:

🧰 Related Projects:

Frequently asked questions

Is DNS-collector free to use?

DNS-collector is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does DNS-collector do?

Grab your DNS logs, detect anomalies, and finally understand what's happening on your network. The missing piece between DNS servers and your data stack.

What is DNS-collector written in?

DNS-collector is primarily written in Go. Its source is publicly available at https://github.com/dmachard/DNS-collector, and it has 570 GitHub stars.