The DNS Activity Page

Introduction

The DNS Activity page helps you investigate DNS activity observed by network sensors in your organization. From this page, you can review domain lookup activity, identify which systems requested specific domains, correlate requests with resolved IP addresses, and export results for further analysis.


The page contains two views:

  • DNS Requests shows individual DNS requests observed on your network.
  • DNS Resolutions shows domains that were resolved, along with related request and resolution details.


This article covers the following topics:


Access & Navigate the DNS Activity Page

The DNS Activity page is accessible from the sidebar's Network section. 



DNS Requests View

The DNS Requests view displays individual DNS lookup activity observed by a network sensor.


Available columns include:

  • Domain Name
  • Name Server
  • Requested (UTC)
  • Requester
  • Resolved IP


Use this view when investigating a specific DNS request or identifying which device requested a domain.


 

DNS Resolutions View

The DNS Resolutions view displays domains that have been resolved and provides additional context about DNS activity across your environment.


Available columns include:

  • Domain Name
  • First Seen (UTC)
  • Last Seen (UTC)
  • Name Server
  • Name Server Count
  • Requester
  • Requesters
  • Resolution Count
  • Resolved IP


Use this view when analyzing DNS trends, reviewing domain resolution history, or investigating communication with a particular destination.



Details View

Select any row in either view to display additional information in the Details panel below the table.



If you need more space to review the information, select the Expand icon to open the details in a larger modal window.


 

Customize the Table

You can customize which columns appear in the table.

  1. Select Edit Columns.
  2. Choose the columns you want displayed.
  3. Clear any columns you do not want to display.
  4. Select Apply.



You can also resize columns by dragging the edge of a column header. To sort a column, select the column header to toggle between ascending and descending order.


 

Search DNS Activity

The search feature is available in both the DNS Requests and DNS Resolutions views.


Use the search bar to:

  • Locate a specific domain.
  • Find activity associated with a particular requester.
  • Search for requests that use a specific name server.
  • Build advanced filters using column-based logic.


To create a search:

  1. Select a column from the search menu.
  2. Choose a logical operator, such as Contains, Equals, or Is Not.
  3. Select a suggested value or enter your own search term.


As you build your query, the search tool displays suggestions to help refine your results.


 

Sort and Filter Results

You can sort results by selecting any column header. 



For more advanced filtering, use logical operators in the search bar.


Examples:

  • Use Is Not to exclude specific values from the results.
  • Use Is Null to display records where a selected field contains no data.


 

Supported Date Formats

When filtering by date or time, the following formats are supported:

  • 2022-11-22T16:35:42
  • 2022-11-22T16:35:42Z
  • 2022-11-22T16:35:42.000
  • 2022-11-22T16:35:42.000+0000

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article