Sponsored Content
Operating Systems Linux Red Hat BIND 9.x log answers to queries Post 302499771 by fpmurphy on Friday 25th of February 2011 10:55:25 AM
Old 02-25-2011
... and the results of turning on query logging are usually found in /var/log/query.log but check your configuration file for the exact location.
 

7 More Discussions You Might Find Interesting

1. UNIX for Dummies Questions & Answers

I Need Some (help)answers Asap

can someone explain the meaning of the following shell commands: 1. who / wc -l 2. who / sort > user_names 3. cat students > new_students 4. current_day='date / cut -cl-3' i would also appreciated if you could tell me some things about the umask 1. what is a good umask value and why? 2.... (2 Replies)
Discussion started by: dakis
2 Replies

2. Shell Programming and Scripting

basic script for yes and no answers

What is the basic syntax for a script that says do you want to do this? y - execute this n - end not y or n - end and print this for example if I want to run this: "Do you want to start this process?" answer if y,Y, or yes then run the following script (do I put the script with... (10 Replies)
Discussion started by: llsmr777
10 Replies

3. UNIX and Linux Applications

MySQL Slow Queries Log: Lock_time

In MySQL's slow queries log, it'll have an entry like this: # User@Host: scc_service @ # Query_time: 43 Lock_time: 0 Rows_sent: 0 Rows_examined: 0 SET timestamp=1237769209; UPDATE loan SET funding_status="scheduled",datetime_approved=now() WHERE loan_id = '00000'; What does Lock_time... (2 Replies)
Discussion started by: zefflyn
2 Replies

4. UNIX for Dummies Questions & Answers

Question and answers

Hello All, I need to prepare for interview. Can any body help me with interview question and answers pls.. Regards, Sam (2 Replies)
Discussion started by: j_panky
2 Replies

5. Red Hat

Bind 9.x cannot log answers to queries

I know this is a duplicate question but the original has never been answered properly. I've got Bind 9.x set up on my box and the logging turned on. I can see queries being logged but I still can't get it to log the answers to those queries. Here is my named.conf file: # File: /etc/named.conf ... (2 Replies)
Discussion started by: Vadim B
2 Replies

6. UNIX for Dummies Questions & Answers

Need answers urgently!!

hello guys!! need 1 favour from u all.. Can u jst tell me the answers for these ques?? 1. ls - l _____ : command to return all files that end with single digit and those with TXT extension 2. ls -l report* _______ : command to return all files that start with the word RPT except those with LOG... (1 Reply)
Discussion started by: Gan_7
1 Replies

7. Programming

Always giving the answers as 1

Hi, I have wrote a python program to sum the numbers in a list.However its giving answer one. Please advise. MyList = Number = int(input("Please enter number:")) for i in range(1, Number + 1): value = int(input("Enter Numbers %d:" %i)) MyList.append(value) total =... (3 Replies)
Discussion started by: nag_sathi
3 Replies
named.stats(4)						     Kernel Interfaces Manual						    named.stats(4)

NAME
named.stats - Contains BIND server statistics DESCRIPTION
The named.stats file contains server statistics for queries to and from hosts in a BIND environment. You can use this data to determine the load on a DNS server and diagnose problems. See the named(8) reference page for information about how to specify the name and location of the named.stats file; the default is /var/tmp/named.stats. The query fields for global and per-node statistics, as specified in the LEGEND section of the named.stats file, are defined as follows: Received a response from a node Received a negative response from a node Received a response from a node that this node had to forward Received an extra answer from a node Received a server failed message (SERVFAIL) from a node Received a format error message (FORMERR) from a node Received some other error from a node Received an zone transfer request mes- sage (AXFR) from a node Received a lame delegation from a node Received some IP options from a node Sent a node a system query Sent a node an answer Forwarded a query to a node Sent a node a retry Sent to a node, but the send failed (in sendto) Received a query from a node Received an inverse query from a node Received a query from a node that this node had to forward Received a retry from a node Received a query using TCP from a node Forwarded a response to a node Sent a node a server failed message (SERVFAIL) Sent a node a format error message (FORMERR) Sent a non-authoritative answer to a node Sent a negative response to a node EXAMPLES
The following example is an excerpt of a named.stats file: +++ Statistics Dump +++ (917839766) Sun Jan 31 22:29:26 1999 370508 time since boot (secs) 370508 time since reset (secs) 130 Unknown query types 711033 A queries 35 NS queries 37 CNAME queries 40 SOA queries 2 MB queries 198963 PTR queries 26088 MX queries 1 TXT queries 20 AAAA queries 60910 ANY queries ++ Name Server Statistics ++ (Legend) RR RNXD RFwdR RDupR RFail RFErr RErr RAXFR RLame ROpts SSysQ SAns SFwdQ SDupQ SErr RQ RIQ RFwdQ RDupQ RTCP SFwdR SFail SFErr SNaAns SNXD (Global) 537 231 479 0 2 10 0 0 5 0 54 56382 479 8 2 38849 3 0 0 6 479 2 5 19057 1285 [0.0.0.0] 0 0 2 0 0 0 0 0 0 0 0 0 0 4 0 0 0 0 0 0 23 1 0 0 0 [4.0.38.18] 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 2 0 0 0 0 0 0 0 0 0 [4.0.147.94] 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 . . . The values in each entry below the (Global) delimeter are separated into five groups, each with five numbers. These groups of numbers cor- relate to the fields in the Legend section of the file, which are separated into similar groups. From the left of an entry, the first field is RR, the next is RNXD, and so on. In the next group of five on the same line, the first field is RFErr, the next is RErr, and so on. In the Global entry, you can see that, in total, there were 537 queries received, 231 negatives responses received, 479 queries that were forwarded to other BIND servers, and so on. Subsequent entries can be interpreted in a similar manner. The Global values in this example are indicative of several problems: RFail = 2 The server received 2 failure messages from a node or nodes. There might be a problem with the nodes that attempted to query the server. Find the IP addresses of the nodes and contact the administrators. RFErr = 10 The server received 10 improperly formatted queries from a node or nodes. If this happens consistently, a hacker might be trying to break into the server. You should run a monitoring tool to collect more data. RLame = 5 The server received 5 lame delegations. This problem occurs if nodes query the server for information regarding a zone for which it has no authority. It is usually a temporary condition, but if the problem persists, contact the nodes' administrators and ask them to check their configurations. RDupR = 8 A node or nodes sent multiple copies of the same query to the server. These errors are usually benign, but nodes should give up after 3 attempts. If the number of duplicates is fairly high, there might be a problem with the nodes or the network. SErr = 2 The server attempted to send 2 queries to a forwarder or forwarders by using the sendto system call, and the attempts failed. Check your configuration and make sure that all of the forwarders you listed are reachable. RIQ = 3 The server received 3 inverse queries. These queries are usually benign, but if the value is fairly high, a hacker might be trying to break into the server. You should run a monitoring tool to collect more data. SFail = 2 The server sent 2 failure messages to a node or nodes. These failures are usually benign, but might not be under certain condi- tions. If the server sends many SFail errors to one node, there might be a problem with that node. If the node is another name- server, it might be lame nameserver. If the node is a host, it is sending abnormal queries. You should find the offending node and resolve the problem. SFerr = 5 The server informed a node or nodes that their requests were improperly formatted. The value of this field usually correlates to the RFErr field. You should find the offending node and resolve the problem. FILES
The syslogd daemon offers a partial listing of the named.stats data in the daemon.log file. RELATED INFORMATION
Commands: named(8), syslogd(8) delim off named.stats(4)
All times are GMT -4. The time now is 04:18 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy