View DNS activity details

In the DNS Activity report, you can view detailed information about DNS traffic that was directed to ETP.

You must be an ETP super administrator or a user with a specific permission to view the DNS Activity report. For more information, see Enterprise Threat Protector roles.

How to

  1. In the navigation menu, select Monitoring > Activity. Click the DNS Activity tab.
    Note: If you are trying the new Enterprise Center interface, in the navigation menu, select Threat Analytics > Activity > DNS Activity.
  2. Filter events as needed. For more information, see Filter data based on date and time and Filter DNS activity data.
  3. If you haven’t done so already, select a dimension.
  4. In the list of grouped events, click the arrow icon that is associated with a dimension value. For example, if you selected Domain, click the arrow icon to see the associated traffic. Logged activity appears in a table format.
  5. Click the information button. Activity details appear in a separate window. You can use the arrow keys on your keyboard to navigate to other activity in the table and show details.