Table of Contents
Lire supports query logs of two DNS servers: Bind 8™ and Bind 9™.
You have to enable query logging in bind, something which is not turned on by default.
Example 7.1. Enabling Query Log In Bind
To enable query logging in Bind 8™ or Bind 9™, you should add
the following to your named.conf
configuration file:
logging {
channel query_logging {
file "/var/log/named_querylog"
versions 3 size 100M;
print-time yes; // timestamp log entries
};
category queries {
query_logging;
};
};
Bind 8™'s query logs contain one entry for each DNS query
made to the name server. It logs the time of the query
(you have to set print-time to
yes for this), the IP of the requesting
client, the name queried, the type of the query and the
protocol. Recursive queries will have a + after
the XX which appears in all query entries.
Example 7.2. Sample Bind 8™ Query Log
10-Apr-2000 00:01:20.307 XX /10.2.3.4/1.2.3.in-addr.arpa/SOA/IN
10-Apr-2000 00:01:20.308 XX+/10.4.3.2/host.foo.com/A/IN