---
title: "Devices"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35375333/Devices"
format: markdown
---
<span style="color: #000000">The </span>*<span style="color: #000000">Devices </span>*<span style="color: #000000">tab includes all security data associated with devices assigned to a policy on your network. You can </span><span style="color: #000000">view of assets identified from your network traffic. </span><span style="color: #000000">To export the All </span>*<span style="color: #000000">Devices </span>*<span style="color: #000000">table data in csv format, click </span>**<span style="color: #000000">Export</span>**<span style="color: #000000">. The default file name is </span>*<span style="color: #000000">security-activity_devices.csv</span>*<span style="color: #000000">. </span><span style="color: #000000">Exported data is limited to 10,000 records. </span>

## <span style="color: #000000">Performing Search Queries </span>  


<span style="color: #000000">The search feature supports using queries to perform searches using the integrated search query language.  Using the search query language, you can search all records in the </span>*<span style="color: #000000">Security Events</span>*<span style="color: #000000"> report with customized queries. Using the search query options available in the </span>*<span style="color: #000000">Devices </span>*<span style="color: #000000">report, you can:</span>

- <span style="color: #000000">Run a search on any of the following fields:</span>
  - **<span style="color: #000000">ACTION</span>**
  - **<span style="color: #000000">CLASS</span>**
  - **<span style="color: #000000">DEVICE NAME</span>**
  - **<span style="color: #000000">DHCP FINGERPRINT</span>**
  - **<span style="color: #000000">DNS VIEW</span>**
  - **<span style="color: #000000">FEED</span>**
  - **<span style="color: #000000">MAC ADDRESS</span>**
  - **<span style="color: #000000">OS VERSION</span>**
  - **<span style="color: #000000">POLICY</span>**
  - **<span style="color: #000000">PROPERTY</span>**
  - **<span style="color: #000000">QUERY</span>**
  - **<span style="color: #000000">QUERY TYPE</span>**
  - **<span style="color: #000000">RESPONSE</span>**
  - **<span style="color: #000000">SOURCE</span>**
  - **<span style="color: #000000">USER</span>**
  - **<span style="color: #000000">THREAT_CONFIDENCE</span>**
  - **<span style="color: #000000">THREAT_LEVEL</span>**
- <span style="color: #000000">The</span>**<span style="color: #000000"> =</span>**<span style="color: #000000"> and the </span>**<span style="color: #000000">NOT (!=)</span>**<span style="color: #000000"> operators</span>
- <span style="color: #000000">Use </span>**<span style="color: #000000">AND</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">OR</span>**<span style="color: #000000"> operators.</span>
- <span style="color: #000000">Use </span>**<span style="color: #000000">single</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">double </span>**<span style="color: #000000">quoted to enter values with spaces.</span>
- <span style="color: #000000">Use parentheses to group search parts. </span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">wildcard symbol (*) </span>**<span style="color: #000000">as the last character of the search value for a partial match.</span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">ENTER</span>**<span style="color: #000000"> key to apply search.</span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">TAB</span>**<span style="color: #000000"> key to autocomplete search with the first available suggestion.</span>

## <span style="color: #000000">Sample Search Queries</span>

<span style="color: #000000">The following are search query examples:</span>

- *<span style="color: #000000">query=domain.* AND device=52.123*</span>*
- <span style="color: #000000">device=office.1.domain.com OR device=office2.domain.com</span>
- <span style="color: #000000">dns_view=example-view AND query_type=A</span>
- <span style="color: #000000">(source=’Infoblox Endpoint’ OR source=“example 1”) AND device=52.123*</span>
  <span style="color: #000000">Search by the query fields matches values by subdomains. E.g. query = domain.com</span>  
<span style="color: #000000">matches</span>  
<span style="color: #000000">'domain.com', 'office.domain.com', 'space.office.domain.com</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">All search values are case sensitive. A maximum of five operators can be used when constructing a query search.</span>

## <span style="color: #000000">Filtering the Devices Tab</span>

<span style="color: #000000">To filter All </span>*<span style="color: #000000">Devices </span>*<span style="color: #000000">events by specific criteria, select the applicable objects from the following drop-down menus located below the top action menu:</span>

- **<span style="color: #000000">Level</span>**<span style="color: #000000">: The threat level for the malicious hit. The threat level can be High, Medium, or Low.</span>  
**<span style="color: #000000">Confidence</span>**<span style="color: #000000">: The threat confidence score assigned to an indicator. The confidence level can be High, Medium, or Low.</span>
- **<span style="color: #000000">Property</span>**<span style="color: #000000">: The nature of the threat. The portal includes all threat properties.</span>
- **<span style="color: #000000">Class</span>**<span style="color: #000000">: </span><span style="color: #000000">The threat intelligence class, such as Phishing, MalwareC2DGA, and others associated with the targeted domain.</span>
- **<span style="color: #000000">Source</span>**<span style="color: #000000">: The location of the device within the network infrastructure. For example, the device can be an </span>**<span style="color: #000000">on-prem</span>**<span style="color: #000000"> appliance or an </span>**<span style="color: #000000">endpoint</span>**<span style="color: #000000"> device. You can select which records to view by selecting or deselecting from among the options available.</span>
- **<span style="color: #000000">OS</span>**<span style="color: #000000">: The operating system of the device. </span>
- **<span style="color: #000000">Show</span>**<span style="color: #000000">: Security and activity events can be filtered by choosing an option from the </span>**<span style="color: #000000">Show</span>**<span style="color: #000000"> drop-down menu. </span>

<span style="color: #000000">The </span>*<span style="color: #000000">All Devices </span>*<span style="color: #000000">table displays the following information by specific criteria. Select the applicable objects from the following column drop-down menus:</span>

- **<span style="color: #000000">DEVICE NAME</span>**<span style="color: #000000">: The name of the device being used when the event was triggered.</span>
- **<span style="color: #000000">REQUESTS</span>**<span style="color: #000000">: The request type. Clicking the number of requests in the </span>**<span style="color: #000000">REQUESTS</span>**<span style="color: #000000"> column associated with a device name, allows you to pivot off the record and display all security events associated with the device name. </span>
- **<span style="color: #000000">SOURCE</span>**<span style="color: #000000">: The location of the device within the network infrastructure. For example, the device can be an </span>**<span style="color: #000000">on-prem</span>**<span style="color: #000000"> appliance or an </span>**<span style="color: #000000">endpoint</span>**<span style="color: #000000"> device.</span>
- **<span style="color: #000000">DHCP FINGERPRINT</span>**<span style="color: #000000">: Identifies IPv4 and IPv6 mobile devices such as laptop computers, tablets, and smartphones on your network. Due to the broadcast and pervasive nature of DHCP, using DHCP fingerprint detection is an efficient way to perform system identification and inventory. You can use DHCP fingerprint detection to track devices on your network. </span>
- **<span style="color: #000000">OS/VERSION</span>**<span style="color: #000000">: The version of the device's operating system making the request.</span>
- **<span style="color: #000000">MAC ADDRESS</span>**<span style="color: #000000">:</span><span style="color: #000000"> The detected MAC address of the device.</span>
- **<span style="color: #000000">USER</span>**<span style="color: #000000">: The user that triggered the hit. For remote offices, the portal displays </span>**<span style="color: #000000">Unknown</span>**<span style="color: #000000"> for these users.</span>
  ***Export Records***
  Click **Export** to download a CSV file of report records. The maximum number of exported Devices report records is **10,000**.