Forum Discussion
Vijay_E
Jun 08, 2016Cirrus
This should log all DNS requests and you can probably grep for the domain name and then do a diff with the domain list that you have:
when DNS_REQUEST {
log local0. "QUERY from ([IP::client_addr]) for [DNS::question name])"
}