Insights / Logs
The full DNS Filtering timeline — every block, who caused it and when. It is the same security timeline used elsewhere in DashX, filtered to the DNS Filtering module.
Open it at Secure Access → DNS Filtering → Insights / Logs.
What to do with it
Investigate an alert. Start from Most blocked on the Overview — a threat domain with a red multi-device counter means several machines are reaching for the same bad host. Click the row to see the exact devices, users, source IPs, hit counts and last-seen times, then open the timeline for the sequence.
Answer "why can't I reach this site?" Look up the domain in Check a domain on the Overview: you get the verdict, the reason, which of your rules matched and the category listings. That takes ten seconds and settles the question.
Prove it for an audit. Export the range you need with Export CSV on the Overview — it follows the selected 7d / 30d / 90d / All range.
Reading a monitored entry
Rows carrying a would-block badge came from a policy in Monitor mode. Nothing was stopped; this is what would have happened. Use them to size the impact of enforcement before you flip a policy to Block.
Retention
Query logs are kept for a rolling window and then rotate out. Export anything you need to hold longer — a compliance report should not depend on live log retention.
When a user complains that a site broke, check the timeline first. Nine times out of ten it is a newly enabled category rather than a network fault, and you can fix it with one allow rule in Custom rules.