Hello John,
If I correctly understood, you want to "mirror" (so, to have an exact copy of DNS traffic) hitting ACE, is this correct?
If so, take a look at this article https://supportforums.cisco.com/docs/DOC-15652 , which describes how to set up a SPAN capture from ACE internal interface.
Note you can filter on VLAN (that is, redirect/capture traffic on particular front-end/back-end VLAN. A bit tricky to make additional filtering on ports/protocols, though... Take a look at VACL captures in the same article as well.
HTH, Amir