Skip to content
Avanet

Analyse Sophos DNS Protection reports and Live Discover

Under My Products > DNS Protection > Reports, you can filter DNS queries, prepare them as reports and export them. For more detailed investigations, use Threat Analysis Center > Live Discover > DNS Protection. There you can investigate DNS records in the Data Lake with built-in or custom SQL queries.

Quick workflow: In Report Generator, select a Report template and Time frame, apply the narrowest practical filters under Query, and click Generate. For Live Discover, first run a built-in DNS Protection query over a short period. Only enable Designer Mode after the built-in query returns data; for a new DNS query, Data Lake must be selected as the Source.

Prerequisites, licensing and data attribution

DNS Protection must already be processing DNS queries. It is therefore useful to have a known active Location or a managed endpoint and a short test period when analysing reports. Report data is 15 to 25 minutes behind real time. Changes to a Location or Policy name can take between 30 minutes and 4 hours to appear in reports.

For a standalone or network-based deployment, DNS Protection belongs to the Xstream licence family. When DNS Protection is deployed to managed endpoints, however, that deployment path is part of Workspace Protection. Workspace Protection and endpoint-deployed DNS Protection are also required for reports to show user and device details from endpoint data.

Live Discover has a separate prerequisite: this query feature requires a Sophos EDR, XDR or MDR entitlement. This entitlement does not replace Workspace Protection for the managed endpoint DNS path. DNS Protection queries use the Data Lake. Endpoint Queries are not the correct data path for this purpose: they query the current state of selected connected devices, whereas Data Lake queries investigate uploaded data.

The source determines how precisely a report can attribute a query:

  • DNS usage shows DNS queries across the network.
  • DNS usage by source attributes network data to a Location. For data from Sophos Endpoint, the report can also identify users and devices.
  • For endpoint data, User shows the user or device name from which the query originated. Device shows the device ID. These columns are available only for Sophos Endpoint.
  • High risk devices shows devices making DNS queries to risky, suspicious or unsecured websites.

This makes the boundary clear: a network-based DNS record does not automatically reveal the identity of the original user or endpoint behind a local resolver. The endpoint integration introduced the additional user- and device-related reporting fields as well as the DNS usage by source and High risk devices templates.

Configure and filter a DNS Protection report

  1. Open My Products > DNS Protection > Reports and select the appropriate Report template in Report Generator.
  2. Under Time frame, select a predefined period or set start and end times with Custom. For the first test, a narrow period around a known DNS query is sufficient.
  3. Under Query, select or enter the column name, enter the filter value and, if necessary, change the operator next to the equals sign.
  4. Add more filters only when they narrow the result meaningfully. Multiple filters are joined with AND, so a row must meet every condition.
  5. Click Generate. The report must also be generated again after you click a table value to add a filter.

The comparison operators work differently:

  • = and != are case-sensitive and test equality or inequality respectively.
  • <, <=, > and >= apply only to numeric values.
  • IN performs a case-sensitive comparison against a comma-separated list of values.
  • ~ and !~ perform case-insensitive matching against a wildcard expression; * is the wildcard.

For a domain test, for example, you can filter for the test domain that was actually queried. The domain name is an environment-specific value and must be replaced with the value used in your own test. If the result is empty, first remove the domain filter and check only the period and Location. This reveals whether the spelling or the combination of multiple filters is excluding the result.

The table initially shows its default columns. You can add more fields using the column selector in the top-right; the available columns depend on the template and data source. Click a column heading to sort in ascending or descending order. When a date column is visible, Sophos groups identical rows according to the period:

  • for 1, 8 or 24 hours, by identical date, hour and minute,
  • for 7 days or Custom up to 7 days, by identical starting hour,
  • for 30 days or Custom over 7 days, by day with 00:00 as the timestamp.

Do not overinterpret Status: For an incorrect, invalid or no-longer-existing URL, Status shows n/a for A, AAAA, CNAME or HTTPS queries and Allowed for other query types. This value alone proves neither the destination’s reachability nor its safety.

Charts are available as Bar, Horizontal bar, Pie, Line or Stack-area. Select the axes using the wrench icon. Changing the chart type resets the axes to that type’s defaults; bar and pie charts show only the ten most frequent categories.

Save, schedule and export a report

Save Template stores Query filters, chart type and axes, table sorting, and table columns under Saved Templates. It does not store data or the time frame. You must therefore select a time frame appropriate to the investigation again the next time you open it. A maximum of 1,000 templates can be stored across DNS Protection, ZTNA and Sophos Firewall reports.

For a one-off handover, select PDF, CSV or HTML. Use Schedule to plan recurring daily, weekly or monthly reports. A Template Name can contain no more than 64 characters, and a maximum of 200 schedules is allowed in total. The export limits are:

  • PDF: 10,000 rows and 15 columns
  • HTML: 10,000 rows and 23 columns
  • CSV: 100,000 rows and 23 columns

Manually generated and scheduled exports appear under Scheduled Exports and are deleted after 90 days. If a report contains personal data, sending a link by email is preferable to sending an attachment: Sophos Fusion credentials are required to open the link. Downloaded files and recipients must nevertheless comply with your own privacy and deletion policy.

Investigate DNS data with Live Discover

  1. Open Threat Analysis Center > Live Discover > DNS Protection.
  2. Select a built-in DNS Protection query. Designer Mode is not required for this.
  3. Under Select a Time Period, first select a short period with known activity and click Run Query. A query can cover no more than 30 days. Split longer investigations into separate, non-overlapping time windows.
  4. Only after the built-in query returns data, enable Designer Mode and inspect the query with Edit, or select Create new query. For a new DNS Protection query, set Source to Data Lake.
  5. In the SQL dialog, open Schema. In the Schema Viewer, select Firewall under Data Lake, then select the xgfw_data table.

This baseline test distinguishes missing data or permissions from an error in a custom query. Do not use a generic SQL template or undocumented fields. Instead, base custom queries on the documented mapping to xgfw_data and the fields actually available in your tenant’s Schema Viewer. Sophos Endpoint Data Collection and Live Discover explains how to select, run and schedule general Data Lake queries.

Documented DNS fields in xgfw_data

Sophos documents the following fields for DNS Protection:

action, bytes, dns_qid, dns_qname, dns_qtype, dns_duration, domain, domain_category, domain_risk, hits, log_type, log_component, object_name, protocol, policy_name, query_class, query_flags, query_size, reason, response_code, response_records_num, response_ip_num, resolved_ip, response_type, response_name, response_class, response_ttl_list, response_size, response, riskscore, security_status, src_ip, src_port, src_location, timestamp.

A log_type value of DNS and a log_component value of FE-DNS identify a DNS Protection log. object_name contains the Domain List name when the Policy action was Reject and the reason was Custom Domain Block or Allow. timestamp indicates when the DNS query was processed, hits is the number of queries, and bytes is the combined query and response size. The response_* fields describe the DNS response; security_status indicates whether DNSSEC was validated for the response.

Although the table is called xgfw_data and appears under Firewall, this does not mean that every other firewall field is populated in DNS records. In particular, this DNS field list documents no fields for User or Device. Before writing a custom query, therefore, check the available fields in your tenant’s Schema Viewer.

Validate results and narrow down problems

For a reproducible functional test, generate a known query from an unambiguously assigned Location or managed pilot endpoint. Then wait 15 to 25 minutes and check:

  1. Does the query appear in the selected report period?
  2. Do the domain, action or status, Policy, and Location match?
  3. For endpoint data, are User and Device populated plausibly?
  4. Does a built-in DNS Protection query in Live Discover return matching records for the same period?

The report remains empty

First check Time frame, time zone, filters, and case for =, != and IN. Then remove filters one by one because all conditions must be met simultaneously. If the broader report still returns nothing, verify that the test actually generated DNS queries and that the expected Location or endpoint data source was used. A Location or Policy that has just been renamed is unsuitable for an immediate test because the change can take between 30 minutes and 4 hours to appear.

User or Device is missing

Check whether the record really originates from Sophos Endpoint. Network-based queries do not contain this endpoint attribution. Then use DNS usage by source and add User and Device with the column selector. If the columns or values are still missing, do not infer a user from the source IP or Location.

Reports show data, but Live Discover does not

First check the EDR, XDR or MDR entitlement, DNS Protection as the category, Data Lake as the Source, the period, and Firewall > xgfw_data. Then run a built-in DNS Protection query unchanged with Run Query. If it works, the error is in the custom query: copy field names directly from Schema and simplify the query step by step. If the built-in query also fails, the safe next step is to check the Data Lake data path or escalate to Support; undocumented fields or joins are not a reliable workaround.

Safe rollback and lifecycle

Reports do not change DNS processing. Removing a filter or discarding an unsaved analysis therefore requires no technical rollback. Before deleting saved artefacts, check whether another administrator or an operational process needs them:

  • Select a schedule under Scheduled Exports and remove it with Delete. Then verify that the schedule generates no further exports.
  • Select a template under Saved Templates and remove it with Delete. You can delete no more than 25 templates in one operation. This deletes the saved report configuration, not the source DNS data.
  • Do not continue using an incorrect custom Live Discover query as a replacement for the built-in query. Return to the known built-in DNS query and a short period.

For ongoing operations, regularly review saved templates and schedules for their owner, purpose, recipients, period, and required columns. In particular, User, Device, domain, and source IP can constitute personal or operationally relevant data. After changes to the endpoint integration, also check whether DNS usage by source continues to identify users and devices. Before making operational changes, check the current help and the fields actually available in the Schema Viewer. Use Release Notes only when you need to trace the historical introduction of a reporting feature.