Entrada - A tool for DNS big data analytics

ENTRADA processes DNS data (PCAP-files) from an input location (local, HDFS or S3) and converts and enriches the data to Apache Parquet format, finally sending the results to one of following endpoints:

See the database schema for more information about all the database columns.

The data is enriched by adding the following details to each row.

Apache Impala, AWS Athena or Apache Spark can be used to analyse the generated Parquet data.

ENTRADA handles the required workflow actions such as:

For more information see the ENTRADA website.

How to use

ENTRADA is deployed using Docker Compose, download one of the example Docker Compose scripts and save it as docker-compose.yml and then edit the script to configure the environment variables to fit your requirements.
Start the container using the docker-compose command:

   docker-compose up

For more more detailed deployment instructions and available onfiguration options see the ENTRADA website.


This project is distributed under the GPLv3, see LICENSE.


When building a product or service using ENTRADA, we kindly request that you include the following attribution text in all advertising and documentation.

This product includes ENTRADA created by <a href="https://www.sidnlabs.nl">SIDN Labs</a>, available from
<a href="http://entrada.sidnlabs.nl">http://entrada.sidnlabs.nl</a>.