Thanks - hadn't spotted that. Now got that enabled, and getting some DNS info in the syslog file. It's not very useful info though:
<14>1 2018-11-03T17:27:46+00:00 MikroTik forward - - - forward: in:bridge1_LAN out:EE Broadband, src-mac 24:5e:be:1d:09:9f, proto UDP, 192.168.1.98:54957->18.104.22.168:53, NAT (192.168.1.98:54957->22.214.171.124:54957)->126.96.36.199:53, len 71
I'd ideally like to see which IPs are resolving which URLs. Is there another way of achieving this other than setting up port mirroring?
You can redirect all DNS requests to your router, I guess this way you will see all of them in DNS log.