---
title: "DNS Users"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35375394/DNS%20Users"
format: markdown
---
*<span style="color: #000000">The Users </span>*<span style="color: #000000">tab provides information on users associated with DNS activity hitting the web filters assigned to a policy on your network. To export the </span>*<span style="color: #000000">Users</span>*<span style="color: #000000"> table data in csv format, click </span>**<span style="color: #000000">Export</span>**<span style="color: #000000">. The default file name is </span>*<span style="color: #000000">dns-activity_users.csv</span>*<span style="color: #000000">. Exported data is limited to 10,000 records. </span>

## <span style="color: #000000">Performing Search Queries </span>  


<span style="color: #000000">The search feature supports using queries to perform searches using the integrated search query language.  Using the search query language, you can search all records in the </span>*<span style="color: #000000">Security Events</span>*<span style="color: #000000"> report with customized queries. Using the search query options available in the </span>*<span style="color: #000000">DNS Users </span>*<span style="color: #000000">report, you can:</span>

- <span style="color: #000000">Run a search on any of the following fields:</span>
  - **<span style="color: #000000">DEVICE NAME</span>**
  - **<span style="color: #000000">DHCP FINGERPRINT</span>**
  - **<span style="color: #000000">DNS VIEW</span>**
  - **<span style="color: #000000">MAC ADDRESS</span>**
  - **<span style="color: #000000">OS VERSION</span>**
  - **<span style="color: #000000">QUERY</span>**
  - **<span style="color: #000000">QUERY TYPE</span>**
  - **<span style="color: #000000">RESPONSE</span>**
  - **<span style="color: #000000">SOURCE</span>**
  - **<span style="color: #000000">USER</span>**

- <span style="color: #000000">The </span>**<span style="color: #000000">= </span>**<span style="color: #000000">and the </span>**<span style="color: #000000">NOT (!=)</span>**<span style="color: #000000"> operators</span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">AND</span>**<span style="color: #000000"> and the </span>**<span style="color: #000000">OR</span>**<span style="color: #000000"> operators.</span>
- <span style="color: #000000">Use </span>**<span style="color: #000000">single</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">double </span>**<span style="color: #000000">quoted to enter values with spaces. </span>
- <span style="color: #000000">Use parentheses to group search parts.</span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">wildcard symbol (*) </span>**<span style="color: #000000">as the last character of the search value for a partial match.</span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">ENTER</span>**<span style="color: #000000"> key to apply search.</span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">TAB</span>**<span style="color: #000000"> key to autocomplete search with the first available suggestion.</span>
  - **<span style="color: #000000">Source</span>**
  - **<span style="color: #000000">Response</span>**
  - **<span style="color: #000000">Query Type</span>**
  - **<span style="color: #000000">Query</span>**
  - **<span style="color: #000000">DNS View</span>**
  - **<span style="color: #000000">Device</span>**
- <span style="color: #000000">Use </span>**<span style="color: #000000">AND</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">OR</span>**<span style="color: #000000"> operators.</span>
- <span style="color: #000000">Use </span>**<span style="color: #000000">single</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">double </span>**<span style="color: #000000">quoted to enter values with spaces.</span>
- <span style="color: #000000">Use parentheses to group search parts. </span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">wildcard symbol (*) </span>**<span style="color: #000000">as the last character of the search value for a partial match.</span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">ENTER</span>**<span style="color: #000000"> key to apply search.</span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">TAB</span>**<span style="color: #000000"> key to autocomplete search with the first available suggestion.</span>

## <span style="color: #000000">Sample Search Queries</span>

<span style="color: #000000">The following are search query examples:</span>

- 
  - *<span style="color: #000000">query=domain.*AND device=52.123*</span>*
  - <span style="color: #000000">device = office1.domain OR device=office2.domain.com</span>
  - <span style="color: #000000">dns_view=example-view AND query_type=A</span>
  - <span style="color: #000000">(source=‘Infoblox Endpoint’ OR source=“example 1”) AND device=52.123*</span>
    <span style="color: #000000">Search by the query fields matches values by subdomains. E.g. query = domain.com</span>  
<span style="color: #000000">matches</span>  
<span style="color: #000000">'domain.com', 'office.domain.com', 'space.office.domain.com</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">All search values are case sensitive. A maximum of five operators can be used when constructing a query search.</span>

## <span style="color: #000000">Filtering the Users Tab</span>

<span style="color: #000000">To filter</span>*<span style="color: #000000"> User </span>*<span style="color: #000000">events by specific criteria, select the applicable objects from the following drop-down menus located below the top action menu:</span>

- **<span style="color: #000000">Source</span>**<span style="color: #000000">: The location of the device within the network infrastructure. For example, the device can be an </span>**<span style="color: #000000">on-prem</span>**<span style="color: #000000"> appliance or an </span>**<span style="color: #000000">endpoint</span>**<span style="color: #000000"> device. You can select which records to view by selecting or deselecting from among the options available. When filtering by source, the filter drop-down is limited to showing 10 sources.</span>
- **<span style="color: #000000">Show</span>**<span style="color: #000000">: Security and activity events can be filtered by choosing an option from the </span>**<span style="color: #000000">Show</span>**<span style="color: #000000"> drop-down menu. </span>

<span style="color: #000000">The </span>*<span style="color: #000000">Users </span>*<span style="color: #000000">table displays the following information by specific criteria, where you can select the applicable objects from the following column drop-down menus: </span>

- **<span style="color: #000000">REQUESTS</span>**<span style="color: #000000">: The request type. Clicking the number of requests in the </span>**<span style="color: #000000">REQUESTS</span>**<span style="color: #000000"> column associated with a user allows you to pivot off the record and display all DNS events associated with the user. </span>
- **<span style="color: #000000">DEVICES</span>**<span style="color: #000000">: The number of devices that are used to access the corresponding DNS content. Clicking the number of requests in the </span>**<span style="color: #000000">DEVICES</span>**<span style="color: #000000"> column associated with a user allows you to pivot off the record and display all DNS events associated with the user. </span>
- **<span style="color: #000000">USER</span>**<span style="color: #000000">: The user that triggered the hit. For remote offices, the portal displays </span>**<span style="color: #000000">Unknown</span>**<span style="color: #000000"> for these users.</span>

## Export Records

Click **Export** to download a CSV file of report records. The maximum number of exported DNS Users report records is **10,000**.