作者hukhuk (ken)
看板Linux
標題[問題] 關於BIND9 Log的問題?
時間Wed Oct 9 21:45:37 2013
Hi all,
最近在玩bind9 dns的服務,仔細看了一下query.log的部份,皆發現只有client去查某個
Domain的資料,卻沒有把此Domain所對映出來的IP給記錄起來,想請問要怎麼調設定呀?
才會把這個部份show出來。以下是query.log的rawdata,
client 192.168.153.1#47418: query: tw.dictionary.yahoo.com IN A + (192.168.153.140)
client 192.168.153.1#28017: query: l.yimg.com IN A + (192.168.153.140)
client 192.168.153.1#31791: query: tw.promo.campaign.yahoo.net IN A + (192.168.153.140)
client 192.168.153.1#41986: query: ads.yimg.com IN A + (192.168.153.140)
client 192.168.153.1#6632: query: tw.linkspot.search.yahoo.com IN A + (192.168.153.140)
client 192.168.153.1#8012: query: 197.254.160.119.in-addr.arpa IN PTR + (192.168.153.140)
client 192.168.153.1#43130: query: csc.beap.bc.yahoo.com IN A + (192.168.153.140)
client 192.168.153.1#22243: query: ads.yldmgrimg.net IN A + (192.168.153.140)
client 192.168.153.1#8012: query: 197.254.160.119.in-addr.arpa IN PTR + (192.168.153.140)
client 192.168.153.1#22243: query: ads.yldmgrimg.net IN A + (192.168.153.140)
client 192.168.153.1#16799: query: apac.analytics.yahoo.com IN A + (192.168.153.140)
client 192.168.153.1#23460: query: 157.206.72.211.in-addr.arpa IN PTR + (192.168.153.140)
client 192.168.153.1#22243: query: ads.yldmgrimg.net IN A + (192.168.153.140)
client 192.168.153.1#18578: query: help.yahoo.com IN A + (192.168.153.140)
client 192.168.153.1#38590: query: tw.edit.yahoo.com IN A + (192.168.153.140)
client 192.168.153.1#8713: query: login.yahoo.com IN A + (192.168.153.140)
client 192.168.153.1#12998: query: www.gamersky.com IN A + (192.168.153.140)
先謝謝各位了
--
※ 發信站: 批踢踢實業坊(ptt.cc)
◆ From: 180.177.216.151
→ danny8376:query當然只記查誰啊 http有access log連頁面內容都記? 10/09 22:21
→ danny8376:到底有啥需要 連結果都要記下來的? 10/09 22:22
→ hukhuk:想從IP反查其domain 10/09 22:26
推 rickieyang:nslookup也可以反查不是? 10/09 22:59