Introduction
The DNS Activity page helps you investigate DNS activity observed by network sensors in your organization. From this page, you can review domain lookup activity, identify which systems requested specific domains, correlate requests with resolved IP addresses, and export results for further analysis.
The page contains two views:
- DNS Requests shows individual DNS requests observed on your network.
- DNS Resolutions shows domains that were resolved, along with related request and resolution details.
This article covers the following topics:
- Access & Navigate the DNS Activity Page
- Details View
- Customize the Table
- Search DNS Activity
- Sort and Filter Results
Access & Navigate the DNS Activity Page
The DNS Activity page is accessible from the sidebar's Network section.

DNS Requests View
The DNS Requests view displays individual DNS lookup activity observed by a network sensor.
Available columns include:
- Domain Name
- Name Server
- Requested (UTC)
- Requester
- Resolved IP
Use this view when investigating a specific DNS request or identifying which device requested a domain.
DNS Resolutions View
The DNS Resolutions view displays domains that have been resolved and provides additional context about DNS activity across your environment.
Available columns include:
- Domain Name
- First Seen (UTC)
- Last Seen (UTC)
- Name Server
- Name Server Count
- Requester
- Requesters
- Resolution Count
- Resolved IP
Use this view when analyzing DNS trends, reviewing domain resolution history, or investigating communication with a particular destination.

Details View
Select any row in either view to display additional information in the Details panel below the table.

If you need more space to review the information, select the Expand icon to open the details in a larger modal window.
Customize the Table
You can customize which columns appear in the table.
- Select Edit Columns.
- Choose the columns you want displayed.
- Clear any columns you do not want to display.
- Select Apply.

You can also resize columns by dragging the edge of a column header. To sort a column, select the column header to toggle between ascending and descending order.
Search DNS Activity
The search feature is available in both the DNS Requests and DNS Resolutions views.
Use the search bar to:
- Locate a specific domain.
- Find activity associated with a particular requester.
- Search for requests that use a specific name server.
- Build advanced filters using column-based logic.
To create a search:
- Select a column from the search menu.
- Choose a logical operator, such as Contains, Equals, or Is Not.
- Select a suggested value or enter your own search term.
As you build your query, the search tool displays suggestions to help refine your results.
Sort and Filter Results
You can sort results by selecting any column header.

For more advanced filtering, use logical operators in the search bar.
Examples:
- Use Is Not to exclude specific values from the results.
- Use Is Null to display records where a selected field contains no data.
Supported Date Formats
When filtering by date or time, the following formats are supported:
- 2022-11-22T16:35:42
- 2022-11-22T16:35:42Z
- 2022-11-22T16:35:42.000
- 2022-11-22T16:35:42.000+0000
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article