The following section outlines the steps to configure DNS Statistics. If you are configuring DNS Statistics to send data to a Splunk server, ensure that you have the Splunk HTTP Event Collector (HEC) host and token information.
To configure DNS Statistics on a DNS/DHCP Server:
In the event of a service disruption, such as a network error or the system crashes, DNS Statistics service attempts to mitigate event loss. If you enable the Disk buffer type, in the event that the system goes down, the messages are copied to disk and sent when the service is restored. In the event of network connectivity issues, the service retries failed requests. There might be a loss of data if the DNS Statistics process stops on the DNS/DHCP Server while DNS service is running and processing DNS statistics.