My company runs Zeek on an Arm embedded device and we would like to minimize the CPU load from Zeek. Is there any way to disable the dns.log, we do not use it.
This email and any files transmitted with it are confidential and proprietary and intended solely for the use of the individual or entity to whom they are addressed. Any dissemination, distribution or copying of this communication is strictly prohibited without our prior permission. If you received this in error, please contact the sender and delete the material from any computer.
You have multiple options here. You can disable the DNS log, but that'd mean that internal DNS-related processing still happens. Therefore it's likely more effective to have Zeek ignore DNS traffic, unless you have other reasons to look at it. The following little script suppresses DNS via a BPF packet filter, and also suppresses the log.
This email and any files transmitted with it are confidential and proprietary and intended solely for the use of the individual or entity to whom they are addressed. Any dissemination, distribution or copying of this communication is strictly prohibited without our prior permission. If you received this in error, please contact the sender and delete the material from any computer.