---
title: "Security Events"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35406000/Security%20Events"
format: markdown
---
<span style="color: #000000">The </span><span style="color: #000000">*Security Events*</span><span style="color: #000000"> tab provides comprehensive security data on your networks over a specific time period. You can view all your security events generated when </span>DNS traffic or DNS queries <span style="color: #000000">match one or more of your policies. </span>Security events are the policy enforcement logs, and may be the source of information for other reports.

## <span style="color: #000000">Performing Search Queries </span>

The search feature allows you to run searches using the integrated search query language. With this language, you can create customized queries to search all records in the Security Events report. Using the available search options, you can run searches on any field displayed in the drop-down list next to the Search button.

- <span style="color: #000000">**ACTION**</span>
- **BYPASS CODE **
- <span style="color: #000000">**CLASS**</span>
- <span style="color: #000000">**DEVICE IP**</span>
- <span style="color: #000000">**DEVICE NAME**</span>
- <span style="color: #000000">**DHCP FINGERPRINT**</span>
- <span style="color: #000000">**DNS VIEW**</span>
- <span style="color: #000000">**FEED**</span><span style="color: #000000"> </span>
- <span style="color: #000000">**MAC ADDRESS**</span>
- <span style="color: #000000">**OS VERSION**</span>
- <span style="color: #000000">**POLICY**</span>
- <span style="color: #000000">**PROPERTY**</span>
- <span style="color: #000000">**QUERY**</span>
- <span style="color: #000000">**QUERY TYPE**</span>
- <span style="color: #000000">**RESPONSE**</span>
- <span style="color: #000000">**SOURCE**</span><span style="color: #000000"> </span>
- <span style="color: #000000">**THREAT CONFIDENCE**</span>
- <span style="color: #000000">**THREAT LEVEL**</span>
- <span style="color: #000000">**USER**</span>
- <span style="color: #000000">The </span><span style="color: #000000">**=**</span><span style="color: #000000"> and the </span><span style="color: #000000">**NOT (!=)**</span><span style="color: #000000"> operators</span>
- <span style="color: #000000">Use </span><span style="color: #000000">**AND**</span><span style="color: #000000"> and </span><span style="color: #000000">**OR**</span><span style="color: #000000"> operators.</span>
- <span style="color: #000000">Use </span><span style="color: #000000">**single**</span><span style="color: #000000"> and </span><span style="color: #000000">**double **</span><span style="color: #000000">quoted to enter values with spaces.</span>
- <span style="color: #000000">Use parentheses to group search parts. </span>
- <span style="color: #000000">Use the </span><span style="color: #000000">**wildcard symbol (*) **</span><span style="color: #000000">as the last character of the search value for a partial match.</span>
- <span style="color: #000000">Use the </span><span style="color: #000000">**ENTER**</span><span style="color: #000000"> key to apply search.</span>
- <span style="color: #000000">Use the </span><span style="color: #000000">**TAB**</span><span style="color: #000000"> key to autocomplete search with the first available suggestion.</span>

## <span style="color: #000000">Sample Search Queries</span>

<span style="color: #000000">The following are search query examples:</span>

- <span style="color: #000000">*query=domain.*AND device=52.123**</span>
- <span style="color: #000000">device=office1.domain OR device=office2.domain.com</span>
- <span style="color: #000000">dns_view=example-view AND query_type=A</span>

<span style="color: #000000">(source=‘infoblox Endpoint’ OR source=“example 1”) AND device=52.123*</span>

<span style="color: #000000">Search by the query fields matches values by subdomains. E.g. query = domain.com</span>  
<span style="color: #000000">matches</span>  
<span style="color: #000000">'domain.com', 'office.domain.com', 'space.office.domain.com</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">All search values are case sensitive. A maximum of five operators can be used when constructing a query search.</span>

## <span style="color: #000000">Filtering the Security Events Tab</span>

<span style="color: #172b4d">To filter </span><span style="color: #000000">*Security Events*</span><span style="color: #172b4d"> by specific criteria, select the applicable objects from the following drop-down menus located below the top action menu. The objects returned in each drop-down are limited to a maximum of 10 returned records, with the exception of the </span><span style="color: #000000">**Feed**</span><span style="color: #172b4d">, </span><span style="color: #000000">**Source**</span><span style="color: #172b4d">, </span><span style="color: #000000">**Policy**</span><span style="color: #000000">, and</span><span style="color: #000000">** Class**</span><span style="color: #172b4d"> filters which are limited to a maximum of 100 returned records.</span>

- <span style="color: #000000">**Action**</span><span style="color: #000000">: The configured action for the security rule. This can be Allow, Redirect, Block, or Log (limited to a maximum of 10 returned records).</span>
- <span style="color: #000000">**Confidence**</span><span style="color: #000000">: The threat confidence score assigned to an indicator. The confidence level can be High, Medium, or Low (limited to a maximum of 10 returned records).</span>
- <span style="color: #000000">**Feed**</span><span style="color: #000000">: The list of threat feeds against which the malicious hit was triggered (limited to a maximum of 100 returned records).</span>
- <span style="color: #000000">**Class**</span><span style="color: #000000">: The threat intelligence feeds, such as Phishing, MalwareC2DGA, and others (limited to a maximum of 100 returned records). </span>
- <span style="color: #000000">**Level**</span><span style="color: #000000">: The threat level for the malicious hit. This can be </span><span style="color: #000000">**High**</span><span style="color: #000000">, </span><span style="color: #000000">**Medium**</span><span style="color: #000000">, </span><span style="color: #000000">**Low**</span><span style="color: #000000">, or </span><span style="color: #000000">**Info**</span><span style="color: #000000">. </span><span style="color: #000000">**Note**</span><span style="color: #000000">: In some cases, a record may not contain all fields which will be represented as </span><span style="color: #000000">**N/A**</span><span style="color: #000000"> on the user interface and </span><span style="color: #000000">**NULL**</span><span style="color: #000000"> in the API results (limited to a maximum of 10 returned records). </span>
- <span style="color: #000000">**Policy**</span><span style="color: #000000">: Active security policies (limited to a maximum of 100 returned records).</span>
- <span style="color: #000000">**Source**</span><span style="color: #000000">: The location of the device within the network infrastructure. For example, the device can be an </span><span style="color: #000000">**on-prem**</span><span style="color: #000000"> appliance or an </span><span style="color: #000000">**endpoint**</span><span style="color: #000000"> device. You can select which records to view by selecting or deselecting from among the options available (limited to a maximum of 100 returned records).</span>
- <span style="color: #000000">**Show**</span><span style="color: #000000">: Security and activity events can be filtered by choosing its time frame from the </span><span style="color: #000000">**Show**</span><span style="color: #000000"> drop-down menu..</span>

<span style="color: #000000">The </span><span style="color: #000000">*Security Events*</span><span style="color: #000000"> table displays the following information by specific criteria. Select the applicable filter objects from the following column drop-down menus. </span>The user can select which fields they want to display in the table.

- <span style="color: #000000">**DETECTED**</span><span style="color: #000000">: The timestamp when the hit was detected.</span>
- <span style="color: #000000">**THREAT LEVEL**</span><span style="color: #000000">: The threat level for the malicious hit. This can be </span><span style="color: #000000">**High**</span><span style="color: #000000">, </span><span style="color: #000000">**Medium**</span><span style="color: #000000">, </span><span style="color: #000000">**Low**</span><span style="color: #000000">, or </span><span style="color: #000000">**Info**</span><span style="color: #000000">. </span><span style="color: #000000">**Note**</span><span style="color: #000000">: In some cases, a record may not contain all fields which will be represented as </span><span style="color: #000000">**N/A**</span><span style="color: #000000"> on the user interface and </span><span style="color: #000000">**NULL**</span><span style="color: #000000"> in the API results. </span>
- <span style="color: #000000">**QUERY**</span><span style="color: #000000">: Displays the domain that sent the DNS query. Clicking the view on Dossier icon associated with a record allows you to view the Dossier threat look-up record of a threat class or property for the selected record. On the Dossier threat look-up page, you can view the Dossier report details for additional information on the selected record. </span>
- <span style="color: #000000">**CLASS**</span><span style="color: #000000">: The threat intelligence class, such as Phishing, MalwareC2DGA, and others.</span>
- <span style="color: #000000">**PROPERTY**</span><span style="color: #000000">: The property or nature of the threat. By default, the portal includes all threat properties.</span>
- <span style="color: #000000">**POLICY**</span><span style="color: #000000">: The security policy against which the malicious hit triggered.</span>
- <span style="color: #000000">**ACTION**</span><span style="color: #000000">: The configured action for the security rule. This can be </span><span style="color: #000000">**Allow**</span><span style="color: #000000">, </span><span style="color: #000000">**Redirect**</span><span style="color: #000000">, </span><span style="color: #000000">**Block**</span><span style="color: #000000">, or </span><span style="color: #000000">**Log**</span><span style="color: #000000">.</span>
- <span style="color: #000000">**DEVICE NAME**</span><span style="color: #000000">: The name of the device.</span>
- <span style="color: #000000">**SOURCE**</span><span style="color: #000000">: The location of the device within the network infrastructure. For example, the device can be an </span><span style="color: #000000">**on-prem**</span><span style="color: #000000"> appliance or an </span><span style="color: #000000">**endpoint**</span><span style="color: #000000"> device. </span>
- <span style="color: #000000">**RESPONSE**</span><span style="color: #000000">: The response taken by Infoblox Platform for the malicious hit.</span>
- <span style="color: #000000">**DNS VIEW**</span><span style="color: #000000">: The DNS version data being served.</span>
- <span style="color: #000000">**FEED**</span><span style="color: #000000">: The name of the threat feed against which the malicious hit triggered.</span>
- <span style="color: #000000">**QUERY TYPE**</span><span style="color: #000000">: The DNS query type.</span>
- <span style="color: #000000">**MAC ADDRESS**</span><span style="color: #000000">: The detected MAC address of the device.</span>
- <span style="color: #000000">**DHCP FINGERPRINT**</span><span style="color: #000000">: The unique identifier that was formed by the values in the DHCP option 55 or 60. This identifier is used to identify the requesting client or device.</span>
- <span style="color: #000000">**USER**</span><span style="color: #000000">: The user that triggered the event. For remote offices, the portal displays </span><span style="color: #000000">**Unknown**</span><span style="color: #000000"> for these users. If you have configured access authentication, this displays the authenticated user who triggered the event.</span>
- <span style="color: #000000">**THREAT CONFIDENCE**</span><span style="color: #000000">: A scoring system for malicious hits where confidence is rated </span><span style="color: #000000">**High**</span><span style="color: #000000">, </span><span style="color: #000000">**Medium**</span><span style="color: #000000">, </span><span style="color: #000000">**Low**</span><span style="color: #000000">.</span>
- **DEVICE**<span style="color: #000000"> </span>**IP**<span style="color: #000000">: The </span>IPv4 or IPv6 <span style="color: #000000">address of the </span>**device**<span style="color: #000000"> responsible for the hit.</span>
- <span style="color: #000000">**OS VERSION**</span><span style="color: #000000">: The version of the device's operating system making the request.</span>
- **INDICATOR**: The policy source from which the indicator type being reported. The indicator can originate from an application or category filter, from a custom list, or from a feed.
- **RESPONSE REGION**: The region within a country where the response originated based on information acquired from the public IP address of <span style="color: #000000">Infoblox </span> Endpoint and DFP,
- **RESPONSE COUNTRY**: The country where the response originated based on information acquired from the public IP address of <span style="color: #000000">Infoblox </span> Endpoint and DFP,
- **DEVICE REGION**: The region within a country where the response originated.
- **DEVICE COUNTRY**: The country where the device resides.
- **BYPASS CODE**: A bypass code used to override the  security event.

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">You can enable and disable custom fields by clicking on the icon located in the top, right-hand corner of the table, and selecting or deselecting which custom fields you want to view. All fields can be selected or deselected, or they can be returned to the default configuration by clicking </span><span style="color: #000000">**Restore to default GRID setting**</span><span style="color: #000000">.</span>

## Export Records

Click **Export** to download a CSV file of report records. The maximum number of exported Security Events report records is **50,000**.