DNS Log

DNS log lists events related to the DNS traffic. To log DNS events on the NGFW, DNS filtering must be enabled in the DNS proxy settings and logging must be enabled in the content filtering rules where DNS traffic is logged.

The following information is displayed:

  • Node

  • Time

  • User

  • Rule

  • Reasons

  • Domain name

  • Source zone

  • Source IP address

  • Source port

  • Source MAC address.

  • Destination zone

  • Destination IP address

  • Destination port

  • Network protocol

  • URL category.

  • Information

Administrators can select to display only the columns they need. To do this, click on any of the columns and set the checkmarks for the columns you want to display in the context menu that appears.

To assist in finding the events of interest, the records can be filtered by various criteria such as the protocol, date range, action, etc.

By clicking Export as CSV, the administrator can save the filtered log data in a .csv file for subsequent analysis.

Click Show to open a window with a detailed event description.