Table of Contents
Lire supports query logs of two DNS servers: Bind 8™ and Bind 9™.
You have to enable query logging in bind, something which is not turned on by default.
Example 7.1. Enabling Query Log In Bind
To enable query logging in Bind 8™ or Bind 9™, you should add
the following to your named.conf
configuration file:
logging { channel query_logging { file "/var/log/named_querylog" versions 3 size 100M; print-time yes; // timestamp log entries }; category queries { query_logging; }; };
Bind 8™'s query logs contain one entry for each DNS query
made to the name server. It logs the time of the query
(you have to set print-time
to
yes
for this), the IP of the requesting
client, the name queried, the type of the query and the
protocol. Recursive queries will have a +
after
the XX
which appears in all query entries.
Example 7.2. Sample Bind 8™ Query Log
10-Apr-2000 00:01:20.307 XX /10.2.3.4/1.2.3.in-addr.arpa/SOA/IN 10-Apr-2000 00:01:20.308 XX+/10.4.3.2/host.foo.com/A/IN