Constrain your search using the threat filter and submit a log query
based on the DNS category, for example,
DNS Category =
'grayware' to view logs that have been determined to be a
grayware domain. To search for other DNS types, replace grayware with
another supported DNS category (ddns, parked, malware, etc). Adjust the
search criteria as necessary for your search, including additional query
parameters (such as the severity level and subtype) along with a date
range.
As in the above example, you can also constrain your search using the
threat filter and submit a log query based on the DNS category, for
example, threat_category.value = 'dns-c2' to view
logs that have been determined to be a C2 domain.
To constrain the search to logs generated by DNS queries that have
passed through the
Advanced DNS Security Resolver from the
Prisma Access Agent connection source, use
the following query parameter:
Security Rule = 'Prisma Access
Agent'.
Select a log entry to view the details of a DNS query.
The threat
Category is displayed in the
General pane of the detailed log view. Other
relevant details about the threat are displayed in their corresponding
windows.
Log entries generated by Prisma Access Agent submitted DNS queries
also provide the following field entries, which can be used to
create more targeted searches:
Source User =
'<prisma_access_agent_user>'—Prisma
Access Agent user identification; typically the email
address or user principal name.
Application = 'dns-over-https'—DNS queries
from Prisma Access Agent users are transmitted exclusively
via DoH.