<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,This is not currently in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-dns-logging/m-p/2689449#M191303</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This is not currently possible at least for now.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
    <pubDate>Sat, 23 May 2015 12:47:37 GMT</pubDate>
    <dc:creator>Vibhor Amrodia</dc:creator>
    <dc:date>2015-05-23T12:47:37Z</dc:date>
    <item>
      <title>Cisco ASA DNS Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-dns-logging/m-p/2689448#M191300</link>
      <description>&lt;P&gt;I was playing around with URL logging on an ASA 5510 the other day. Pretty neat. But I was wondering if you could do a similar thing with DNS queries. I setup a regex to match anything and setup a class that referenced the regex. Then, I created a DNS inspection policy map that references the class and logs the matches. However, it only logs something similar to "410004 - DNS Classification: Received DNS query (id: xxxxx) for host x.x.x.x and so on" I was wondering if there was a way to actually log the domain being queried, similar to the URL logging? Here is the example setup just for reference. This would work great if I had some specific domain (or list of domains) I was interested in, but in this case I want to log any DNS query and see the domain being queried for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regex matchall "."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;class-map type inspect dns match-any re.dnsQueries&lt;/P&gt;&lt;P&gt;&amp;nbsp;match domain-name regex matchall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy-map type inspect dns dnsQueries&lt;/P&gt;&lt;P&gt;&amp;nbsp; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; class re.dnsQueries&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inspection dns dnsQueries&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-dns-logging/m-p/2689448#M191300</guid>
      <dc:creator>MikeO5422</dc:creator>
      <dc:date>2019-03-12T05:59:08Z</dc:date>
    </item>
    <item>
      <title>Hi,This is not currently</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-dns-logging/m-p/2689449#M191303</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This is not currently possible at least for now.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Sat, 23 May 2015 12:47:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-dns-logging/m-p/2689449#M191303</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-23T12:47:37Z</dc:date>
    </item>
  </channel>
</rss>

