Primary log:
DNS Server log file creation at 6/5/2007 11:03:53 PM UTC
Log file wrap at 6/6/2007 8:19:04 AM
Message logging key (for packets - other items use a subset of these fields):
Field # Information Values
------- ----------- ------
1 Date (in yyyymmdd format)
2 Time (in 24-hour hh:mm:ss format)
3 Thread ID
4 Context
5 UDP/TCP indicator
6 Send/Receive indicator
7 Remote IP
8 Xid (hex)
9 Query/Response R = Response
blank = Query
10 Opcode Q = Standard Query
N = Notify
U = Update
? = Unknown
11 [ Flags (hex)
12 Flags (char codes) A = Authoritative Answer
T = Truncated Response
D = Recursion Desired
R = Recursion Available
13 ResponseCode ]
14 Question Name
20070606 08:19:44 DCC PACKET UDP Rcv 10.1.1.3 7b3a Q [0000 NOERROR] (10)contoso2(3)com(0)
UDP question info at 0000000000B35C80
Socket = 460
Remote addr 10.1.1.3, port 1538
Time Query=199017, Queued=0, Expire=0
Buf length = 0x0500 (1280)
Msg length = 0x0020 (32)
Message:
XID 0x7b3a
Flags 0x0000
QR 0 (QUESTION)
OPCODE 0 (QUERY)
AA 0
TC 0
RD 0
RA 0
Z 0
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 0
NSCOUNT 0
ARCOUNT 0
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(10)contoso2(3)com(0)"
QTYPE SOA (6)
QCLASS 1
ANSWER SECTION:
empty
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
empty
20070606 08:19:44 DCC PACKET UDP Snd 10.1.1.3 7b3a R Q [8084 A R NOERROR] (10)contoso2(3)com(0)
UDP response info at 0000000000B35C80
Socket = 460
Remote addr 10.1.1.3, port 1538
Time Query=199017, Queued=0, Expire=0
Buf length = 0x0200 (512)
Msg length = 0x0040 (64)
Message:
XID 0x7b3a
Flags 0x8480
QR 1 (RESPONSE)
OPCODE 0 (QUERY)
AA 1
TC 0
RD 0
RA 1
Z 0
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 1
NSCOUNT 0
ARCOUNT 0
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(10)contoso2(3)com(0)"
QTYPE SOA (6)
QCLASS 1
ANSWER SECTION:
Offset = 0x0020, RR count = 0
Name "[C00C](10)contoso2(3)com(0)"
TYPE CNAME (5)
CLASS 1
TTL 3600
DLEN 20
DATA (7)appsrv1(9)ourcompanymfg[C017](3)com(0)
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
empty
20070606 08:19:52 DF0 PACKET UDP Snd 10.1.1.7 69f2 Q [0000 NOERROR] (10)nt_domain1(0)
UDP question info at 0000000000B35C80
Socket = 484
Remote addr 10.1.1.7, port 53
Time Query=0, Queued=0, Expire=0
Buf length = 0x0500 (1280)
Msg length = 0x001c (28)
Message:
XID 0x69f2
Flags 0x0000
QR 0 (QUESTION)
OPCODE 0 (QUERY)
AA 0
TC 0
RD 0
RA 0
Z 0
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 0
NSCOUNT 0
ARCOUNT 0
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(10)nt_domain1(0)"
QTYPE SOA (6)
QCLASS 1
ANSWER SECTION:
empty
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
empty
20070606 08:19:52 DCC PACKET UDP Rcv 10.1.1.7 69f2 R Q [8084 A R NOERROR] (10)nt_domain1(0)
UDP response info at 0000000000B385C0
Socket = 484
Remote addr 10.1.1.7, port 53
Time Query=199025, Queued=0, Expire=0
Buf length = 0x0500 (1280)
Msg length = 0x0061 (97)
Message:
XID 0x69f2
Flags 0x8480
QR 1 (RESPONSE)
OPCODE 0 (QUERY)
AA 1
TC 0
RD 0
RA 1
Z 0
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 1
NSCOUNT 0
ARCOUNT 1
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(10)nt_domain1(0)"
QTYPE SOA (6)
QCLASS 1
ANSWER SECTION:
Offset = 0x001c, RR count = 0
Name "[C00C](10)nt_domain1(0)"
TYPE SOA (6)
CLASS 1
TTL 3600
DLEN 41
DATA
PrimaryServer: (10)sc-domctl1[C00C](10)nt_domain1(0)
Administrator: (5)admin[C00C](10)nt_domain1(0)
SerialNo = 927
Refresh = 900
Retry = 600
Expire = 86400
MinimumTTL = 3600
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
Offset = 0x0051, RR count = 0
Name "[C028](10)sc-domctl1[C00C](10)nt_domain1(0)"
TYPE A (1)
CLASS 1
TTL 3600
DLEN 4
DATA 10.1.1.7
20070606 08:20:09 1304 PACKET UDP Snd 10.1.1.3 0000 N [0024 A NOERROR] (10)contoso2(3)com(0)
UDP question info at 0000000000B385C0
Socket = 484
Remote addr 10.1.1.3, port 53
Time Query=0, Queued=0, Expire=0
Buf length = 0x0500 (1280)
Msg length = 0x0063 (99)
Message:
XID 0x0000
Flags 0x2400
QR 0 (QUESTION)
OPCODE 4 (NOTIFY)
AA 1
TC 0
RD 0
RA 0
Z 0
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 1
NSCOUNT 0
ARCOUNT 0
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(10)contoso2(3)com(0)"
QTYPE SOA (6)
QCLASS 1
ANSWER SECTION:
Offset = 0x0020, RR count = 0
Name "[C00C](10)contoso2(3)com(0)"
TYPE SOA (6)
CLASS 1
TTL 3600
DLEN 55
DATA
PrimaryServer: (7)domctl1(6)ourcompany(5)local(0)
Administrator: (10)hostmaster[C034](6)ourcompany(5)local(0)
SerialNo = 10
Refresh = 900
Retry = 600
Expire = 86400
MinimumTTL = 3600
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
empty
20070606 08:20:09 DCC PACKET UDP Rcv 10.1.1.3 0000 R N [00a4 A NOERROR] (10)contoso2(3)com(0)
UDP response info at 0000000000B3A2D0
Socket = 484
Remote addr 10.1.1.3, port 53
Time Query=199042, Queued=0, Expire=0
Buf length = 0x0500 (1280)
Msg length = 0x0063 (99)
Message:
XID 0x0000
Flags 0xa400
QR 1 (RESPONSE)
OPCODE 4 (NOTIFY)
AA 1
TC 0
RD 0
RA 0
Z 0
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 1
NSCOUNT 0
ARCOUNT 0
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(10)contoso2(3)com(0)"
QTYPE SOA (6)
QCLASS 1
ANSWER SECTION:
Offset = 0x0020, RR count = 0
Name "[C00C](10)contoso2(3)com(0)"
TYPE SOA (6)
CLASS 1
TTL 3600
DLEN 55
DATA
PrimaryServer: (7)domctl1(6)ourcompany(5)local(0)
Administrator: (10)hostmaster[C034](6)ourcompany(5)local(0)
SerialNo = 10
Refresh = 900
Retry = 600
Expire = 86400
MinimumTTL = 3600
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
empty
20070606 08:20:09 48C PACKET UDP Rcv 10.1.1.3 6340 Q [0000 NOERROR] (10)contoso2(3)com(0)
UDP question info at 0000000000B32780
Socket = 460
Remote addr 10.1.1.3, port 1538
Time Query=199042, Queued=0, Expire=0
Buf length = 0x0500 (1280)
Msg length = 0x0020 (32)
Message:
XID 0x6340
Flags 0x0000
QR 0 (QUESTION)
OPCODE 0 (QUERY)
AA 0
TC 0
RD 0
RA 0
Z 0
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 0
NSCOUNT 0
ARCOUNT 0
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(10)contoso2(3)com(0)"
QTYPE SOA (6)
QCLASS 1
ANSWER SECTION:
empty
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
empty
20070606 08:20:09 48C PACKET UDP Snd 10.1.1.3 6340 R Q [8084 A R NOERROR] (10)contoso2(3)com(0)
UDP response info at 0000000000B32780
Socket = 460
Remote addr 10.1.1.3, port 1538
Time Query=199042, Queued=0, Expire=0
Buf length = 0x0200 (512)
Msg length = 0x0040 (64)
Message:
XID 0x6340
Flags 0x8480
QR 1 (RESPONSE)
OPCODE 0 (QUERY)
AA 1
TC 0
RD 0
RA 1
Z 0
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 1
NSCOUNT 0
ARCOUNT 0
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(10)contoso2(3)com(0)"
QTYPE SOA (6)
QCLASS 1
ANSWER SECTION:
Offset = 0x0020, RR count = 0
Name "[C00C](10)contoso2(3)com(0)"
TYPE CNAME (5)
CLASS 1
TTL 3600
DLEN 20
DATA (7)appsrv1(9)ourcompanymfg[C017](3)com(0)
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
empty
20070606 08:20:21 1304 PACKET UDP Snd 10.1.1.3 0000 N [0024 A NOERROR] (10)contoso2(3)com(0)
UDP question info at 0000000000B32780
Socket = 484
Remote addr 10.1.1.3, port 53
Time Query=0, Queued=0, Expire=0
Buf length = 0x0500 (1280)
Msg length = 0x0063 (99)
Message:
XID 0x0000
Flags 0x2400
QR 0 (QUESTION)
OPCODE 4 (NOTIFY)
AA 1
TC 0
RD 0
RA 0
Z 0
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 1
NSCOUNT 0
ARCOUNT 0
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(10)contoso2(3)com(0)"
QTYPE SOA (6)
QCLASS 1
ANSWER SECTION:
Offset = 0x0020, RR count = 0
Name "[C00C](10)contoso2(3)com(0)"
TYPE SOA (6)
CLASS 1
TTL 3600
DLEN 55
DATA
PrimaryServer: (7)domctl1(6)ourcompany(5)local(0)
Administrator: (10)hostmaster[C034](6)ourcompany(5)local(0)
SerialNo = 11
Refresh = 900
Retry = 600
Expire = 86400
MinimumTTL = 3600
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
empty
20070606 08:20:21 DCC PACKET UDP Rcv 10.1.1.3 0000 R N [00a4 A NOERROR] (10)contoso2(3)com(0)
UDP response info at 0000000000B35C80
Socket = 484
Remote addr 10.1.1.3, port 53
Time Query=199054, Queued=0, Expire=0
Buf length = 0x0500 (1280)
Msg length = 0x0063 (99)
Message:
XID 0x0000
Flags 0xa400
QR 1 (RESPONSE)
OPCODE 4 (NOTIFY)
AA 1
TC 0
RD 0
RA 0
Z 0
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 1
NSCOUNT 0
ARCOUNT 0
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(10)contoso2(3)com(0)"
QTYPE SOA (6)
QCLASS 1
ANSWER SECTION:
Offset = 0x0020, RR count = 0
Name "[C00C](10)contoso2(3)com(0)"
TYPE SOA (6)
CLASS 1
TTL 3600
DLEN 55
DATA
PrimaryServer: (7)domctl1(6)ourcompany(5)local(0)
Administrator: (10)hostmaster[C034](6)ourcompany(5)local(0)
SerialNo = 11
Refresh = 900
Retry = 600
Expire = 86400
MinimumTTL = 3600
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
empty