BIND 9.11.4 dnstap not capturing updates

greg.rabil at greg.rabil at
Fri Aug 3 17:05:36 UTC 2018

That would be the update response, but not the update request.


From: bind-users [mailto:bind-users-bounces at] On Behalf Of Darcy, Kevin
Sent: Friday, August 3, 2018 12:56 PM
To: bind-users at
Subject: Re: BIND 9.11.4 dnstap not capturing updates

I'm no expert in DNSTAP, but I see this in the output:

opcode: UPDATE

along with proper reinterpretations of the sections:


How is that "not record[ing} the DNS update"? Are you looking for something prettier? More detailed?

                                                                                   - Kevin

On Fri, Aug 3, 2018 at 7:36 AM, Tony Finch <dot at<mailto:dot at>> wrote:
greg.rabil at<mailto:greg.rabil at> <greg.rabil at<mailto:greg.rabil at>> wrote:

> I use nsupdate to send a DDNS update to my zone, which is added
> successfully.  However, the dnstap.output does not record the DNS
> update.

I think (arguably) this is a limitation of the dnstap specification. It's
defined in a Protocol Buffers declaration file (see the link below) and it
only specifies message types for normal queries and responses. The types
correspond roughly to tap points in the code - it isn't as low-level as
you might expect, if you are imagining something that hooks into the
network IO layer.

If you want to record other kinds of messages (UPDATE, NOTIFY, etc.) it
would probably be best to extend the dnstap `Type` enum, and add
corresponding dns_dt_send() calls to BIND's code. But you should check
with Robert Edmonds first :-)

f.anthony.n.finch  <dot at<mailto:dot at>>
Sole, Lundy, Fastnet, Irish Sea: Variable 3 or 4. Smooth or slight. Fog
patches. Moderate, occasionally very poor, becoming good for a time.
Please visit to unsubscribe from this list

bind-users mailing list
bind-users at<mailto:bind-users at>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>

More information about the bind-users mailing list