Skip to content
Configure BIND9 logging on Ubuntu

Configure BIND9 logging on Ubuntu

To send BIND9 logs to a dedicated file instead of syslog on Ubuntu:

  1. Add a logging section to any named.conf* file:

    logging {
        channel bind_log {
            file "/var/log/named.log";
            print-time yes;
            print-category yes;
            print-severity yes;
        };
        category default { bind_log; };
        category xfer-in { bind_log; };
        category xfer-out { bind_log; };
        category update { bind_log; };
        category security { bind_log; };
        category queries { bind_log; };
    };
  2. Allow BIND to write the file in AppArmor by adding this line to /etc/apparmor.d/usr.sbin.named:

    /var/log/named.log rw,
  3. Reload the AppArmor profile: apparmor_parser -r /etc/apparmor.d/usr.sbin.named

  4. Restart BIND: service bind9 restart

Last updated on