Solved

How to make bind(named) to log down all the DNS usages?

Posted on 2001-07-04
10
211 Views
Last Modified: 2013-12-15
 I want my DNS server to log down all the usages of my network, By default, named only log down itself's boot and shutdown messages. I think in the configfile:/etc/named.conf should be some items can make it work, but I can't find it. Please Let me know!

Thanks Please.
0
Comment
Question by:auther_bin
  • 5
  • 4
10 Comments
 
LVL 3

Expert Comment

by:mrn060900
Comment Utility
I'm not sure I fully understand your question, but take a look at http://www.ph.ed.ac.uk/~richards/linuxdocs/lasg-www/logging/ it may answer your question.

Regards Mike
www.unixonline.co.uk
0
 
LVL 51

Expert Comment

by:ahoffmann
Comment Utility
bind 9.x has the -d option
0
 
LVL 1

Author Comment

by:auther_bin
Comment Utility
Oh dear ahoffmann whould you like to see more details about the "-d" option?
0
 
LVL 51

Accepted Solution

by:
ahoffmann earned 50 total points
Comment Utility
what's the problem with:  man named  ?
...

     -d      set the daemon's debug level to debuglevel. Debugging traces from
             named become more verbose as the debug level increases.
...
?-)
0
 
LVL 51

Expert Comment

by:ahoffmann
Comment Utility
.. also see the THE LOGGING STATEMENT in  man named.conf
0
Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

 
LVL 1

Author Comment

by:auther_bin
Comment Utility
I think you do not clearly know what I means, I am not want to log down debug messges, But to let named to logdown all the usage of DNS service. Just like:
 If user A quest to the server about domain name "yahoo.com" and then server answered "xxx.xxx.xxx.xxx" and, at the same time, process "named" writing to the logfile (/var/log/messages) about this request and answer. Maybe looked like:

Jun 5 12:11:31 user A ask www.yahoo.com.......
0
 
LVL 51

Expert Comment

by:ahoffmann
Comment Utility
I agree that -d is not what want, but see my last comment just a minute later ;-)
The logging should do what you want.
0
 
LVL 1

Author Comment

by:auther_bin
Comment Utility
I tried like this in /etc/named.conf file

logging {
        channel default_syslog {
                file "/var/log/messages";
                syslog daemon;        # send to syslog's daemon facility
                severity info;        # only send priority info and higher
        };
        category default { default_syslog; default_debug; };
        category panic { default_syslog; };
};

bue Can't logdown all the request. Am I right? or the require messages not in category: default_syslog?



0
 
LVL 51

Expert Comment

by:ahoffmann
Comment Utility
bind 9.x is very complex. I also get not fully used to it, so can't give more detailed answes, sorry.
0
 
LVL 1

Author Comment

by:auther_bin
Comment Utility
It's so easy! I know now the last anwser should be:

add these in the named.conf file
----------------------------------------------------------logging {
        channel my_syslog {
                syslog daemon;
                severity info;
        };
        category queries { my_syslog; };
};
----------------------------------------------------------

Thanks ahoffmann !
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Network Interface Card (NIC) bonding, also known as link aggregation, NIC teaming and trunking, is an important concept to understand and implement in any environment where high availability is of concern. Using this feature, a server administrator …
I am a long time windows user and for me it is normal to have spaces in directory and file names. Changing to Linux I found myself frustrated when I moved my windows data over to my new Linux computer. The problem occurs when at the command line.…
Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now