unbound with DNSTAP?

  • I wanted to invest some time into my network analytics, and was thinking of using some of the native output methods rather than syslogs & I was going to start with DNSTAP.

    Is this a really bad idea (is there a gotcha I’m missing?) and am I right that I will need a custom build of unbound and I should build it on another FreeBSD box and copy it over?

