Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In the current dmachard/DNS-collector project, choose capture filters in the input collector, DNS-aware filters and sampling in pipeline transformers, and local file retention in the file logger. These controls do different jobs: packet filters act at capture, transformer rules act on DNS records, and file rotation limits local log files. The project’s configuration uses config.yml; confirm settings against the release you run.

Where each kind of setting belongs

Goal Configure it in What it controls
Select packets or choose where DNS data comes from Input collector Capture source and, where supported, packet-level filtering
Filter DNS records or reduce their volume Pipeline transformer Rules based on DNS fields, general downsampling, or heavy-hitter handling
Limit locally stored log files File logger Rotation by size and file count, plus optional compression and post-rotation handling

The project describes collecting DNS telemetry from live capture, DNStap streams, or stored files, then processing and routing it to outputs. Do not confuse its configuration with the older CZ.NIC project of a similar name; that is a different tool. See the current project README.

How do I filter DNS packets in DNS-Collector?

Choose the input collector for the data source

The collector guide lists AF_PACKET, XDP, DNStap over TCP or UNIX sockets (including TLS-encrypted streams), and PCAP or DNStap file ingestion. AF_PACKET is documented with BPF support. XDP filtering operates at the kernel level, and the project marks the XDP collector as beta in its collector overview. Choose the collector based on where the DNS data originates and where you want filtering to occur. See the collector documentation.

A packet capture filter and a DNS-aware message rule are not interchangeable. A packet filter works at the input/capture layer; rules such as filtering by queried domain or response code belong in a transformer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
SonicWall TZ280 2.5 Gbps Next-Gen Firewall Appliance, HW Only
  • APPLIANCE ONLY: Hardware unit sold without a service subscription — security services, firmware updates and support are NOT included and must be purchased separately to activate protection.
  • PERFORMANCE: Up to 2.5 Gbps firewall inspection, 1 Gbps threat prevention and 1.2 Gbps IPSec VPN throughput driven by SonicWall's patented Reassembly-Free Deep Packet Inspection (RFDPI) engine.
  • CONNECTIVITY: 8x1GbE + 2x1G SFP in a desktop form factor; zero-touch deploy and manage on-box or via cloud Network Security Manager (NSM).
  • THREAT PROTECTION: SonicOS 8 delivers intrusion prevention, gateway anti-malware, application control, TLS/SSL decryption, Capture ATP multi-engine sandboxing (RTDMI) and reputation-based content & DNS filtering with an active service subscription.
  • BUILT FOR SMALL BUSINESS & BRANCH: Secure SD-WAN, IPSec and SSL VPN plus Zero-Trust Network Access through Cloud Secure Edge keep distributed sites and remote workers protected.

Use the filtering transformer for DNS fields

The documented default pipeline sequence places filtering after normalization. Its controls cover downsampling and allow/drop filtering by domain, client or server IP, and response code. Use these when the decision depends on parsed DNS data rather than only on packets visible to the capture mechanism. The transformer guide describes the available filtering options and ordering.

If you set a custom transformer order, only transformers named in that order are initialized. An enabled transformer omitted from the custom order is therefore not applied; check both the transformer configuration and the order.

Rank #2
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed, Integrated Wireless Radios, Threat Protection, and Cloud Management (02-SSC-2823)
  • SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
  • Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
  • Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
  • Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
  • Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.

How does DNS-Collector sampling work?

General downsampling

The filtering transformer’s downsampling reduces data volume by a percentage. It is a general sampling choice, not a mechanism that first identifies unusually frequent query names or other keys. The exact configuration keys and accepted values should be checked in the documentation for your installed release.

Adaptive sampling for heavy hitters

The separate frequency-filtering transformer identifies high-frequency keys and applies a configured action. The official documentation extract gives these defaults: enable: false, target: "qname", threshold-heavy: 1000, action-on-heavy: "drop", sample-rate: 100, ttl: 300, and max-capacity: 500000. These are published configuration defaults, not performance measurements; verify them against the exact release deployed because they can be version-sensitive. See the frequency-filtering documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
SonicWall TZ270 High Availability | Gen7 Firewall HA Model, Requires Secondary Unit - Not a Standalone Device | Redundant Appliance for Continuous Network Uptime and Failover (02-SSC-6447)
  • SonicWall TZ270 High Availability Unit (02-SSC-6447) - Seamless Failover Protection: Designed to pair with a primary SonicWall firewall for automatic failover and continuous network uptime. Not a Standalone unit - requires an identical primary SonicWall appliance; cannot function independently.
  • Defends against ransomware, malware, intrusions, and encrypted threats using Reassembly-Free Deep Packet Inspection (RFDPI), Real-Time Deep Memory Inspection (RTDMI), and Capture ATP cloud sandboxing.
  • Flexible connectivity with eight Gigabit Ethernet interfaces, USB ports, and Zero-Touch deployment to simplify remote rollout and reduce IT workload.
  • Built-in SD-WAN, site-to-site VPN, and TLS 1.3 decryption help optimize bandwidth, secure hybrid work, and inspect threats hidden inside encrypted traffic.
  • Supports up to 750,000 concurrent connections for reliable performance and room to grow as cloud usage and devices increase.

The documented actions have different data consequences:

  • drop discards heavy-hitter queries.
  • sample retains one in every sample-rate heavy-hitter queries.
  • tag keeps the queries and adds frequency metadata.

The ttl is described as a sliding-window half-life in seconds: counts are halved at each interval. Sampling or dropping loses events by design; tagging preserves queries but adds metadata. Select the action based on whether the priority is lower volume or retaining the underlying query records.

Rank #4
Dualcomm PCIe 1G-10G Packet Capture Card, Network TAP Card (ETAP-PC10G)
  • NIC + Network TAP in a Single PCIe Card. Combines the functionality of a PCIe network interface controller (NIC) with an integrated network tap, delivering seamless access to 1G or 10G Ethernet links without requiring external TAP hardware.
  • Dual SFP Connectors: Offers maximum flexibility with support for both copper and fiber connectivity, ensuring compatibility with diverse network setups.
  • Ultra-Low Latency. Built for speed, this card ensures minimal delay, making it perfect for high-performance, latency-sensitive applications.
  • Space-Efficient and Security-Optimized Design. Ideal for building network monitoring and security appliances, this card eliminates the need for an external TAP box, saving rack space and reducing costs while ensuring seamless packet capture and monitoring capabilities.
  • Broad Compatibility. Compatible with Intel Ethernet Adapter drivers, enabling smooth integration across Windows, Linux, and VMware ESXi platforms.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How do I set log retention or rotation?

For local file output, the file logger documents max-size: 100 and max-files: 10 as defaults. These govern rotation by size and the number of files retained. The documentation also lists max-batch-size: 65536, flush-interval: 1, and compress: false. Those are logger settings too, but they do not replace the size and file-count rotation controls. Consult the file logger documentation for the configuration and units applicable to your release.

Compression is optional: when enabled, completed files are gzip-compressed asynchronously, with only one compression task running at a time. A postrotate-command can run a script after rotation, for example to move completed logs into an archive workflow. The documentation does not prescribe a retention period in days. These settings govern the file logger, not retention in a database, Kafka topic, or SIEM; set those destinations’ retention policies separately.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
SonicWall TZ280 2.5 Gbps Firewall, Secure Upgrade Adv 3-Yr + CSE NGFW
  • SECURE UPGRADE PLUS PROGRAM (3-Yr, Advanced Edition): SonicWall upgrade path that bundles a new TZ280 appliance with the Advanced Protection Suite (APSS). REQUIREMENTS: for customers upgrading from an existing SonicWall firewall; a qualifying prior unit may be required at registration. Includes 1 year of Cloud Secure Edge (CSE) Zero-Trust Network Access.
  • SERVICE BUNDLE – ADVANCED PROTECTION SUITE (APSS): all Essential services plus Capture ATP cloud sandboxing with patented RTDMI, advanced DNS security, cloud Network Security Manager (NSM) management, reporting & analytics, and 24/7 support — SonicWall's recommended all-in security suite.
  • PERFORMANCE: Up to 2.5 Gbps firewall inspection, 1 Gbps threat prevention and 1.2 Gbps IPSec VPN throughput driven by SonicWall's patented Reassembly-Free Deep Packet Inspection (RFDPI) engine.
  • CONNECTIVITY: 8x1GbE + 2x1G SFP in a desktop form factor; zero-touch deploy and manage on-box or via cloud Network Security Manager (NSM).
  • BUILT FOR SMALL BUSINESS & BRANCH: Secure SD-WAN, IPSec and SSL VPN plus Zero-Trust Network Access through Cloud Secure Edge keep distributed sites and remote workers protected.

Configure and validate without mixing layers

  1. Identify whether your DNS data arrives from live interface capture, DNStap, or stored PCAP/DNStap files.
  2. Choose the input collector, applying packet-level filters there where supported. Use the filtering transformer for domain, IP, response-code, and general downsampling rules.
  3. Decide whether you want general percentage downsampling or heavy-hitter handling. For frequency filtering, set and verify the target, threshold, action, sample rate, TTL, and capacity; choose tagging if preserving the queries matters.
  4. For local file output, set rotation size and file count to fit disk constraints. Add compression or a post-rotation command only if it suits your archive process.
  5. Validate the YAML before deployment with ./dnscollector -config config.yml -test-config. The configuration guide also documents SIGHUP reload behavior. Match keys and defaults to the installed release rather than assuming the moving main documentation describes it exactly.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.