I am looking for dns request + answer, but the logs does not contain them. Is there anyway to log those, or just see them somehow in a file, or in the cache?
If you want to see DNS requests to public DNS, you can try creating a new PF rule for port 53 (UDP is the default, but there are some programs that will use TCP), make it rule # 1, be certain that logging is enabled for this rule.
Also remember that if you've configured according to DNS Best Practice, most internal DNS requests will be satisfied by your internal name server's cache.
For some reason it did not work, and not having a hub on my network, I used Cain to do ARP poisoning between the box and Astaro, then I was able to monitor the traffic I needed.