In this article
Follow this guide to navigate the DNS Query Log. The log represents all DNS traffic to the DNSFilter account and is available in Standard and MSP dashboard views.
The DNS Query Log has many uses, including quickly finding the who, what, when, and where of any DNS query to troubleshoot filtering policies and manage policy settings with the Actions menu. The view is customizable, and data can be exported via email.
From the DNSFilter dashboard, navigate to Reporting and select DNS Query Log.
The default Standard account view opens to all DNS queries from the last 5 minutes.
When viewing the DNS Query Log from the MSP dashboard, apply top-level filters to load data (more on data filters below).
All plan tiers include query data retention up to the last 9 days. The Time and Actions columns are pinned to the left and right of the table.
Data Filters
Filter the DNS Query Log to view the query data that matters most. Filter data from 3 options: the top-level, quick filters, and data grid.
Top-level filters
Edit these filters and select Apply to load data. Start typing in any selector to find a specific item quickly.
Organization. Required for MSP dashboard access. Select an Organization to load data. All other filter fields stay disabled until an Organization is selected.
Site. Multi-select, with a Select All option.
Roaming Client/Relay. Multi-select, with a Select All option.
Users. Multi-select, with a Select All option.
Time. Select a preset range or set a custom date range up to the previous 9 days.
Quick filters
The All, Allowed, Blocked, and Threats bar above the grid also acts as a quick filter.
Grid filters
Refine the data set with additional grid filters, including FQDN, domain categories, and deployment type.
Example Use Case: Help Desk Ticket
Resolve a ticket reporting blocked content that should be allowed: filter around the time of the report, select the affected user or Roaming Client, and use the Blocked quick filter to isolate the related DNS traffic. Use the Actions menu to update the policy Allow or Block Lists.
Customize the log view
Beyond filtering, the DNS Query Log offers several ways to adjust how data displays.
Column Presets. The column preset dropdown in the grid toolbar switches between predefined column sets without managing columns individually. Available presets are Default, Investigative, Compliance Audit, and All.
Data Columns. Under Preferences, show or hide columns, and search the column list to find one quickly. Show or hide all columns in one selection. Columns can be reordered and resized by dragging, and any column can be pinned by right-clicking the column menu.
The default view includes Time, FQDN, Result, Method, Categories, Site, Policy, Deployment, Local User Name, and Actions.
Row Density. Select how to view rows: compact (most dense), standard, or comfortable (least dense).
Export Data. Export a filtered data set via email in one selection.
⚠️ Data export limitations. Exports are limited to 50,000 records, and larger jobs do not complete. To export more than 50,000 records, narrow the results with filters, or avoid the limit with the Data Export add-on.
Save View. Save a customized view to reuse its column layout, and reset it with Use Default. Save View does not save filters, only column layout.
As a workaround, the log writes filter state to the URL, so bookmarking a filtered view captures its filters and shares them across sessions and shares.
Refresh. The grid does not update data until a refresh is triggered. Select the in-app or browser refresh to load the latest data.
Actions menu
The Actions menu is useful to quickly add/remove a specific domain to/from the Allow List, Block List (or multiple at once), or in AppAware for the Organization's Filtering Policies—all without leaving the DNS Query Log.
- Locate the domain to update by using data filters
- Select the Actions menu
- Select the applicable action
- Update the domain
The Filtering Policy will automatically update as new settings save and allow/block DNS traffic according to the updated requirements.
Comments
0 comments
Please sign in to leave a comment.