Palo Alto Networks Knowledgebase: How to Create a Custom Report for Suspicious DNS Queries

How to Create a Custom Report for Suspicious DNS Queries

2683
Created On 09/25/18 19:21 PM - Last Updated 08/05/19 19:48 PM
Reporting and Logging
Resolution

Overview

The Palo Alto Networks firewall observes certain domains to be associated with malware and malicious activity. If multiple threat signatures from a single host are present, this may indicate that the host is compromised. Custom reports can be created to help detect the infected hosts, so that they can be quarantined.

 

This document describes how to create a custom report on DNS queries that are categorized as suspicious or malware.

 

Steps

  1. Navigate to Monitor > Manage Custom Reports and click Add.
  2. Set the Database field to Threat log, under Detailed logs (Slower).
  3. Enter the query (under Query Builder) as (subtype eq spyware) and (app eq dns).

 

When the report is run, the output may look similar to the following:

 

Note: The report can be exported to PDF, CSV, or XML format, as desired.

 

owner: kadak



Attachments
Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClWGCA0&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Attachments
Choose Language