Project

General

Profile

Actions

Feature #12939

closed

Extend DNS query log

Added by Louis B about 3 years ago. Updated about 3 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
DNS Resolver
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default

Description

Hello,

I would like to monitor which computer is trying to reach which URL. I also like to block certain URL's. For those purposes I try to force DNS-lookups via DNS-redirect to the pfSense resolver.

After doing so and adding "server: log-queries: yes" (https://docs.netgate.com/pfsense/en/latest/troubleshooting/dns-queries.html)
the DNS-querys are logged in "System Logs/DNS-resolver, however ......... without the related interface/GW and without the IP address of the computer initiating the query

In the mean time I noticed that it is possible to get a bit more info by adding
log-queries: yes
log-replies: yes
#log-tag-queryreply: yes
That does at least provide, in the reply, the IP-address of the querying computer.

It would be nice to have some improvements here which makes at possible see which URL's are queried from where
(and to import that elsewhere for further analyses

Actions

Also available in: Atom PDF