Skip to content

Dnstap emit tax

What does sampled vs fuller dnstap emission cost versus dnstap off?

Numbers are same-host comparisons on a single reference host and are not service-level objectives. See the performance hub disclaimer.

When this matters

Event export (dnstap / events) is powerful for traffic forensics and can tax the datapath when emitting query/response surfaces. Export is designed to stay off the DNS hot path — a full queue drops events rather than delaying client replies — but producers still pay to build and enqueue frames. Compare sinks off, sampled (~10% responses), and fuller emit under the same forward_fast load before enabling broad production capture. Lab walkthrough: Event export and dnstap.

What we varied

Evidence

Feature tax — dnstap off / sampled / full (forward_fast)

Feature tax — dnstap off / sampled / full (forward_fast)

Download CSV

Posture Runtime Achieved QPS Avg latency (ms) Sent Completed Lost Workers
dnstap_off sync 77696.7 25.7 778975 778975 0 ingress=2
dnstap_sampled sync 73759.2 27.1 739578 739578 0 ingress=2
dnstap_full sync 68939.9 28.9 692386 692386 0 ingress=2

At a glance

  • dnstap off / sampled / full (forward_fast): dnstap_sampled costs about 5% QPS versus dnstap_off (~74k vs ~78k); dnstap_full costs about 11% QPS versus dnstap_off (~69k vs ~78k).

Takeaway

Dnstap costs scale with how much you emit. Versus dnstap off on this lab (~78k), sampled emit costs about 5% QPS (~74k), and full emit about 11% (~69k).

What to do: leave dnstap off until you have a consumer. Prefer sampled for standing capture; turn on fuller emit only for surfaces you will store and query. Configure emit under What to emit / events. If scrape is also on, see Combined metrics + dnstap.

Member scenarios