Re: Log internal DNS server requests...




"Karl Rhodes" <googlegroups@xxxxxxxxxxxxx> wrote in message
news:c0eb6ed5-9911-4ecd-aa3f-742d1d4f6961@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi guys, Im sure this is a simple thing to do, but I'd like to log DNS
requests made to our internal DNS server.

Full logging is available for Win2003 server on the Debug Logging tab.

In particular, I'd like to log which IP address/workstation made the
request, the url requested and the time the request was made.

I've had a quick look at the logging options in DNS management console
(Windows Server 2003) and have seen the Dubug Loggin and Even Logging
options but non of these seem to be recording what I want, even after
I turned on all the options.

That will usually produce TOO MUCH information unless you have
a very small domain/network.

You must however turn on Debug Logging in 5 places (5 checkboxes).

Enable it, and pick (at least) one item from each of the four categories:

Request/response
Inbound/Outbound
UDP/TCP
Resolution & Transfers vs. other stuff (e.g., notifications/updates)

I read a post which said it can be done via "Advanced Logging", but
cant see an option for this anywhere. Could someone please tell me how
to turn this on and off?

Probably meant Debug Logging but was being sloppy.

I understand that this could seriously slow down a DNS server, but it
will only be used on out internal server and only for a short period.

Maybe not (slow down) but it does produce a LOT of output
faster than most people expect (unless you have small network
w/ few queries.)


.



Relevant Pages

  • Help! Cookies & HttpWebRequest & browser ctl
    ... Is it possible to set cookies for a browser control if I make the request to ... the server using System.Net.HttpWebRequest? ... Basically I'm logging into a server using HttpWebRequest (from my c# ...
    (microsoft.public.inetsdk.programming.webbrowser_ctl)
  • Re: RDP Sessions not "disconnecting"
    ... You can logon to the Console as Admin and Disconnect instead of logging off and this will leave Admin logged on to Synch Act and will leave 2 more Remote slots open. ... The other choice is to disconnect from a normal session as Admin instead of Logging off and when you connect again you will resume your session. ... server based apps - she also hits it from remote. ...
    (microsoft.public.windows.server.sbs)
  • Re: NDR delivery delayed errors keep coming, any advice?
    ... I have turned on the logging as you requested, and when I get a DNR 4.4.7, I ... The sending server tried to ... Delivery status notifications in Exchange Server and in Small Business ... The SMTP logging files are located in ...
    (microsoft.public.windows.server.sbs)
  • Re: Login Errors Seem to indicate we are being hacked?
    ... As an example, my Sonicwall keeps a log that I can read from the regular UI, as well as having the ability to report to a syslog server or e-mail out the log info. ... thing on the box using that authentication package. ... The SMTP or IIS logs should answer everything. ... I'm not familiar with that particular router or its logging capabilities, ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange 2007 distribution group creation
    ... I checked this and they all have level 1 diagnostic logging. ... your DCs that your Exchange server talks to. ... universal distribution group in exchange management console. ...
    (microsoft.public.exchange.admin)