Review GCP DNS policy query logging

Associate the DNS logging policy with its VPC and verify actual query records.

Description

DNS query logs support internal traffic analysis and incident investigation. Disabling policy logging can leave insufficient information about queries from associated networks.

The policy must be associated with the target VPC. It does not replace every DNS path or public-zone logging configuration, and cached responses may not be logged for each request.

Potential impact

  • Malicious domain lookups or abnormal queries may be discovered late.
  • Insufficient query records can hinder incident investigation.

Remediation

  • Set enable_logging = true and associate the policy with the target VPC through networks.
  • Send queries from that network, verify Cloud Logging collection, and configure retention and access permissions.

Examples

These excerpts compare the logging option. Supply networks and project settings separately. Inbound forwarding need not be enabled when it is not required.

Before

hcl
resource "google_dns_policy" "policy" {
  name                      = "example-policy"
  enable_inbound_forwarding = true

  enable_logging = false
}

After

hcl
resource "google_dns_policy" "policy" {
  name                      = "example-policy"
  enable_inbound_forwarding = true

  enable_logging = true
}

Explanation:

  • Before: Query logging is disabled for this policy.
  • After: Query logging is enabled. Verify network association and log arrival for actual collection.

References