In this article
Follow this guide to navigate the DNS Query Log. The log represents all DNS traffic to the DNSFilter account and is available in Standard and MSP dashboard views.
Use the DNS Query Log to review DNS traffic and manage policy settings with the Actions menu. The view is customizable, and data can be exported via email.
To access the log, from the DNSFilter dashboard, navigate to Reporting and select DNS Query Log.
The default Standard account view opens to all DNS queries from the last 5 minutes.
When viewing the DNS Query Log from the MSP dashboard, apply top-level filters to load data (more on data filters below).
All plan tiers include query data retention up to the last nine days. The Time and Actions columns are pinned to the left and right of the table.
Data filters
Filter the DNS Query Log to view the query data that matters most. Filter data from two sources: the top-level bar (including More Filters) and quick filters.
Top-level filters
Edit these filters and enter text in any selector to find a specific item quickly. Select Apply to load data using both the top-level filters and any More Filters column filters together in a single query. The following top-level filters are available:
- Organization: Required for MSP dashboard access. Select an Organization to load data. All other filter fields remain disabled until an Organization is selected
- Site: Multi-select, with a Select All option
- Roaming Client/Relay: Multi-select, with a Select All option
- Users: Multi-select, with a Select All option
- Time: Select a preset range or set a custom date range up to the previous nine days
Quick filters
Use the All, Allowed, Blocked, or Threats bar above the grid as a quick filter.
More Filters
Select More Filters in the top-level bar to open a column filter panel with the following filters:
FQDN
Result
Categories
Threat
Application
Policy
Collection Name
Deployment Type
Deployment OS
Query Type
The Categories filter supports two operators:
Includes: Shows only rows matching the selected categories (default behavior)
Does Not Include: Excludes rows matching the selected categories. Supports multi-select, allowing multiple categories to be excluded in a single filter. An active Does Not Include filter appears as its own chip in the filter bar.
One filter per column can be active at a time, and up to all nine can be active simultaneously. + Add Filter disables if all filters are active.
✍️ Selecting Remove All clears column filters only. Top-level filters are not affected.
Example use case: help desk ticket
Resolve a ticket reporting blocked content that should be allowed: filter around the time of the report, select the affected user or Roaming Client, and use the Blocked quick filter to isolate the related DNS traffic. Use the Actions menu to update the policy Allow or Block Lists.
Customize the log view
Beyond filtering, the DNS Query Log offers several ways to adjust how data displays:
Column presets
The column preset dropdown in the grid toolbar switches between predefined column sets without managing columns individually. Available presets are Default, Investigative, Compliance Audit, and All
Columns
Under Preferences, select Columns to open a checklist of available columns to display. Search the list to find a specific column quickly, or use Show/Hide All to show or hide all columns at once. Columns can be reordered and resized by dragging. Select the three-dot icon (⋮) on any column header to pin, filter, or hide that column. The default view includes the following columns: Time, FQDN, Result, Method, Categories, Site, Policy, Deployment, Local User Name, and Actions
Density
Under Preferences, select Density to choose how rows display: Compact (most dense), Standard, or Comfortable (least dense)
Export
Select Export to send a filtered data set via email in one step.
⚠️ Data export limitations: Exports are limited to 50,000 records, and larger jobs do not complete. To export more than 50,000 records, narrow the results with filters, or avoid the limit with the Data Export add-on.
Save View
Under Preferences, select Save View to save a customized view to reuse its column layout, and reset it with Use Default. Save View does not save filters, only column layout.
As a workaround, the log writes filter state to the URL, so bookmarking a filtered view captures its filters and shares them across sessions and shares.
Refresh
The grid does not update data until a refresh is triggered. Select Refresh in the app or refresh from the browser to load the latest data.
Actions menu
The Actions menu provides quick actions on any query row without leaving the DNS Query Log: update Allow or Block Lists, adjust AppAware settings for the Organization's Filtering Policies, or investigate the activity around a single query.
Add to Allow and Block Lists or AppAware
Update Allow and Block Lists or AppAware settings directly from a query row:
Locate the domain using the data filters
Select the Actions more options menu (···)
Select the applicable action
Select Update
The Filtering Policy updates automatically as the new settings save.
Investigate Mode
The Investigate Mode action scopes the log to the DNS activity around a single row, instead of manually setting up filters.
From the Actions menu, select Investigate Mode
In the modal, select a time window (±5s, ±10s, or ±15s) to view DNS activity within that range
The log filters to the row's deployment (its Roaming Client or Relay, or its Site when no deployment is recorded) within the selected time window.
While in an investigative view, adjust the time window without reopening the modal. Select Exit Investigation to clear the investigative filters and return to the standard view.
Comments
0 comments
Please sign in to leave a comment.