Description
DNS query logs support internal traffic analysis and incident investigation. Disabling policy logging can leave insufficient information about queries from associated networks.
The policy must be associated with the target VPC. It does not replace every DNS path or public-zone logging configuration, and cached responses may not be logged for each request.
Potential impact
- Malicious domain lookups or abnormal queries may be discovered late.
- Insufficient query records can hinder incident investigation.
Remediation
- Set
enable_logging = trueand associate the policy with the target VPC throughnetworks. - Send queries from that network, verify Cloud Logging collection, and configure retention and access permissions.
Examples
These excerpts compare the logging option. Supply networks and project settings separately. Inbound forwarding need not be enabled when it is not required.
Before
hcl
resource "google_dns_policy" "policy" {
name = "example-policy"
enable_inbound_forwarding = true
enable_logging = false
}
After
hcl
resource "google_dns_policy" "policy" {
name = "example-policy"
enable_inbound_forwarding = true
enable_logging = true
}
Explanation:
- Before: Query logging is disabled for this policy.
- After: Query logging is enabled. Verify network association and log arrival for actual collection.