---
title: "Threat  Insight"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35375296/Threat%20%20Insight"
format: markdown
---
<span style="color: #000000">You can view </span><span style="color: #000000">data exfiltration events, including DNS Tunneling detection on the </span>*<span style="color: #000000">Threat Insight</span>*<span style="color: #000000"> tab.</span><span style="color: #000000">The</span>*<span style="color: #000000"> Threat Insight </span>*<span style="color: #000000">tab consolidates all data exfiltration, malware, command, and control events into a single report. The Threat Insight tab rolls up data exfiltration events associated with a host/domain, providing a list of highly correlated events. It lists the devices that experience malicious activities on your network. By default, the report is filtered by all networks/scopes, all users, all security policies, and all devices over a 24-hour time frame. To export the </span>*<span style="color: #000000">Threat Insight</span>*<span style="color: #000000"> table data in csv format, click </span>**<span style="color: #000000">Export</span>**<span style="color: #000000">. The default file name is </span>*<span style="color: #000000">security-activity_threat-insight.csv</span>*<span style="color: #000000">. Exported data is limited to 10,000 records.</span>

## <span style="color: #000000">Performing Search Queries </span>

<span style="color: #000000">The search feature supports using queries to perform searches using the integrated search query language.  Using the search query language, you can search all records in the </span>*<span style="color: #000000">Security Events</span>*<span style="color: #000000"> report with customized queries. Using the search query options available in the </span>*<span style="color: #000000">Threat Insight </span>*<span style="color: #000000">report, you can:</span>

- <span style="color: #000000">Run a search on any of the following fields:</span>
  - **<span style="color: #000000">CONFIDENCE</span>**
  - **<span style="color: #000000">DETECTIONS</span>**
  - **<span style="color: #000000">TARGET DOMAIN</span>**
  - **<span style="color: #000000">THREAT CLASS</span>**
  - **<span style="color: #000000">THREAT FAMILY</span>**
  - **<span style="color: #000000">THREAT LEVEL</span>**
  - <span style="color: #000000">The</span>**<span style="color: #000000"> =</span>**<span style="color: #000000"> and the </span>**<span style="color: #000000">NOT (!=)</span>**<span style="color: #000000"> operators.</span>
- <span style="color: #000000">Use </span>**<span style="color: #000000">AND</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">OR</span>**<span style="color: #000000"> operators.</span>
- <span style="color: #000000">Use </span>**<span style="color: #000000">single</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">double </span>**<span style="color: #000000">quoted to enter values with spaces.</span>
- <span style="color: #000000">Use parentheses to group search parts. </span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">wildcard symbol (*) </span>**<span style="color: #000000">as the last character of the search value for a partial match.</span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">ENTER</span>**<span style="color: #000000"> key to apply search.</span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">TAB</span>**<span style="color: #000000"> key to autocomplete search with the first available suggestion.</span>

## <span style="color: #000000">Sample Search Queries</span>

<span style="color: #000000">The following are search query examples:</span>

- *<span style="color: #000000">target_domain=domain.*</span>*
- <span style="color: #000000">target_domain=domain.* AND confidence=High</span>

<span style="color: #000000">Search by the target_domain field matches values by subdomains. E.g. target_domain = domain.com</span>  
<span style="color: #000000">matches</span>  
<span style="color: #000000">'domain.com', 'office.domain.com', 'space.office.domain.com</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">All search values are case sensitive. A maximum of five operators can be used when constructing a query search.</span>

## <span style="color: #000000">Filtering the Threat Insight Tab</span>

<span style="color: #000000">To filter </span>*<span style="color: #000000">Threat Insight</span>*<span style="color: #000000"> events by specific criteria, select the applicable objects from the following drop-down menus located below the top action menu:</span>

- **<span style="color: #000000">Level</span>**<span style="color: #000000">: The threat level for the malicious hit. This can be </span>**<span style="color: #000000">High</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Medium</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Low</span>**<span style="color: #000000">, or </span>**<span style="color: #000000">Info</span>**<span style="color: #000000">.</span>
- **<span style="color: #000000">Policy</span>**<span style="color: #000000">: Active security policies.</span>
- **<span style="color: #000000">Source</span>**<span style="color: #000000">: The location of the device within the network infrastructure. For example, the device can be an </span>**<span style="color: #000000">on-prem</span>**<span style="color: #000000"> appliance or an </span>**<span style="color: #000000">endpoint</span>**<span style="color: #000000"> device. You can select which records to view by selecting or deselecting from among the options available. </span>
- **<span style="color: #000000">Show</span>**<span style="color: #000000">: Security and activity events can be filtered by choosing an option from the </span>**<span style="color: #000000">Show</span>**<span style="color: #000000"> drop-down menu. </span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">Depending on the availability of data records, not all filter options may be displayed.</span>

<span style="color: #000000">The </span>*<span style="color: #000000">Threat Insight </span>*<span style="color: #000000">table displays the following information by specific criteria. Select the applicable objects from the following column drop-down menus:</span>

- **<span style="color: #000000">ACTIONS</span>**<span style="color: #000000">: </span><span style="color: #000000">The configured action for the security rule. This can be </span>**<span style="color: #000000">Allow</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Redirect</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Block</span>**<span style="color: #000000">, or </span>**<span style="color: #000000">Log</span>**<span style="color: #000000">.</span>
- **<span style="color: #000000">CONFIDENCE</span>**<span style="color: #000000">: The confidence level for the malicious hit. A </span>**<span style="color: #000000">High</span>**<span style="color: #000000"> confidence level means that the hit was likely to be real.</span><span style="color: #000000"> </span>
- **<span style="color: #000000">DETECTIONS</span>**<span style="color: #000000">: The number of detections associated with the report. Clicking on a record's number of detections will display a table of the detections with detailed information associated with the target domain.</span>
- **<span style="color: #000000">TARGET DOMAIN</span>**<span style="color: #000000">: The domain the threat is targeting. Displays the domain that sent the DNS query. Clickingthe view on Dossier icon associated with a record allows you to view the Dossier threat look-up record of a threat class or property for the selected record. On the Dossier threat look-up page, you can view the Dossier report details for additional information on the selected record.</span>
- **<span style="color: #000000">THREAT CLASSES</span>**<span style="color: #000000">: The threat intelligence class, such as Phishing, MalwareC2DGA, and others.</span>
- **<span style="color: #000000">THREAT FAMILY</span>**<span style="color: #000000">: </span><span style="color: #000000">Threat</span><span style="color: #000000"> family</span><span style="color: #000000"> is</span><span style="color: #000000"> a</span><span style="color: #000000"> grouping</span><span style="color: #000000"> of</span><span style="color: #000000"> malicious</span><span style="color: #000000"> threats. For information, see </span>*[Threat Classes and Threat Families](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/193134696)*.
- **<span style="color: #000000">THREAT LEVEL</span>**<span style="color: #000000">: The target domain's threat level rating. This can be </span>**<span style="color: #000000">High</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Medium</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Low</span>**<span style="color: #000000">, or </span>**<span style="color: #000000">Info</span>**<span style="color: #000000">.</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">You can enable and disable custom fields by clicking on the icon located in the top, right-hand corner of the table, and selecting or deselecting which custom fields you want to view. All fields can be selected or deselected, or they can be returned to the default configuration by clicking </span>**<span style="color: #000000">Restore to default GRID setting</span>**<span style="color: #000000">.</span>

## Export Records

Click **Export** to download a CSV file of report records. The maximum number of exported Threat insight report records is **10,000**.