The DNS Reports Page

Introduction

The DNS Reports page in the Network section provides access to all DNS Reports generated for your organization. These reports help administrators investigate DNS activity, review network communications associated with DNS requests, and analyze activity that may be relevant to security investigations.


This article covers the following topics:


Access & Navigate the DNS Reports Page

The DNS Reports page is accessible from the sidebar's Network section. 


 

List View

The DNS Reports page displays all available DNS Reports in a table view (shown above). You can customize the table to suit your workflow by:

  • Resizing columns
  • Rearranging columns
  • Showing or hiding columns
  • Sorting data by column


Details View

Select a report to display additional information in the Details pane at the bottom of the page. 


 

You can expand the Details view into a larger modal window by selecting the Expand icon.



Edit Columns

To customize the columns shown in the table:

  1. Click Edit Columns.
  2. Select the columns you want displayed.
  3. Clear any columns you want hidden.
  4. Click Apply.



You can also adjust column widths by dragging the edge of a column header. To sort information within a column, select the column header to switch between ascending and descending order.



Open a DNS Report

To view a report, select View Report for the desired DNS Report.



Each report contains the following tabs:


TabDescription
OverviewDisplays a summary of the DNS Report.
Resolved IPsShows IP addresses that were returned from DNS requests.
DNS RequestsDisplays DNS lookup activity and resolution details.
CommunicationsShows communications associated with resolved destinations.
ConnectionsDisplays related network connection activity.
ProcessesIdentifies processes involved in the observed activity.


Most tabs are displayed as tables and include detailed information that can be sorted and filtered.



Search DNS Reports

Use the search bar to locate specific DNS Reports or create advanced queries.


When building a query:

  • Select a column.
  • Choose a logic operator, such as Contains, Is Not, or Is Null.
  • Select a suggested value or enter your own search criteria.


As you build a query, the system presents suggestions based on the selected column and available data.


 

You can also perform simple keyword searches without creating a structured query.


Example Searches:

  • Find reports generated during a specific time period.
  • Locate reports associated with a particular hostname.
  • Review reports related to an investigation.


Sort and Filter DNS Reports

Sorting and filtering can help narrow large report sets and focus on the information most relevant to your investigation.


To sort results:

  • Select a column header to sort ascending or descending.
  • Use Order By options available in the search interface. 


To filter results:

  • Use Is Not to exclude specific values.
  • Use Is Null to identify records with no value in a selected field.



Supported Date Formats

The following date formats can be used when filtering by date or time:

  • 2022-11-22T16:35:42
  • 2022-11-22T16:35:42Z
  • 2022-11-22T16:35:42.000
  • 2022-11-22T16:35:42.000+0000


Export DNS Reports

You can export either the full DNS Reports list or a filtered subset of results by selecting the Export .csv icon.


Exports can be useful when:

  • Performing offline analysis
  • Sharing report data with stakeholders
  • Supporting investigations and incident reviews


The CSV file is downloaded to your system's default download location.



Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article