---
title: "Web Content"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35406046/Web%20Content"
format: markdown
---
<span style="color: #000000">The</span>*<span style="color: #000000"> Web Content </span>*<span style="color: #000000">tab provides information on DNS activity hitting the web filters for devices assigned to a policy on your network. You can </span><span style="color: #000000">View events based on domain categorization policies. </span><span style="color: #000000">To export the </span>*<span style="color: #000000">Web Content Request</span>*<span style="color: #000000"> table data in csv format, click </span>**<span style="color: #000000">Export</span>**<span style="color: #000000">. The default file name is </span>*<span style="color: #000000">security-activity_web-content.csv</span>*<span style="color: #000000">. </span><span style="color: #000000">Exported data is limited to 50,000 records. </span>

## <span style="color: #000000">Performing Search Queries </span>  


<span style="color: #000000">The search feature supports using queries to perform searches using the integrated search query language.  Using the search query language, you can search all records in the </span>*<span style="color: #000000">Security Events</span>*<span style="color: #000000"> report with customized queries. Using the search query options available in the </span>*<span style="color: #000000">Web Content </span>*<span style="color: #000000">report, you can:</span>

- <span style="color: #000000">Run a search on any of the following fields:</span>
  - **ACTION**
  - **CATEGORY**
  - **DEVICE IP**
  - **DEVICE NAME**
  - **QUERY **
  - **POLICY**
  - **USER**
- <span style="color: #000000">The</span>**<span style="color: #000000"> =</span>**<span style="color: #000000"> and the </span>**<span style="color: #000000">NOT (!=)</span>**<span style="color: #000000"> operators</span>
- <span style="color: #000000">Use </span>**<span style="color: #000000">AND</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">OR</span>**<span style="color: #000000"> operators.</span>
- <span style="color: #000000">Use </span>**<span style="color: #000000">single</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">double </span>**<span style="color: #000000">quoted to enter values with spaces.</span>
- <span style="color: #000000">Use parentheses to group search parts. </span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">wildcard symbol (*) </span>**<span style="color: #000000">as the last character of the search value for a partial match.</span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">ENTER</span>**<span style="color: #000000"> key to apply search.</span>
- <span style="color: #000000">Use the </span>**<span style="color: #000000">TAB</span>**<span style="color: #000000"> key to autocomplete search with the first available suggestion.</span>

## <span style="color: #000000">Sample Search Queries</span>

<span style="color: #000000">The following are search query examples:</span>

- *<span style="color: #000000">query=domain.*AND device=52.123*</span>*

<span style="color: #000000">device=office1.domain OR device=office2.domain.com</span>

<span style="color: #000000">Search by the query fields matches values by subdomains. E.g. query = domain.com</span>  
<span style="color: #000000">matches</span>  
<span style="color: #000000">'domain.com', 'office.domain.com', 'space.office.domain.com</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">All search values are case sensitive. A maximum of five operators can be used when constructing a query search.</span>

## <span style="color: #000000">Filtering the Web Content Tab</span>

<span style="color: #000000">To filter </span>*<span style="color: #000000">Web Content</span>*<span style="color: #000000"> events by specific criteria, select the applicable objects from the following drop-down menus located below the top action menu:</span>

- **<span style="color: #000000">Action</span>**<span style="color: #000000">: The configured action for the security rule. This can be </span>**<span style="color: #000000">Allow</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Redirect</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Block</span>**<span style="color: #000000">, or </span>**<span style="color: #000000">Log</span>**<span style="color: #000000">.</span>
- **<span style="color: #000000">Category</span>**<span style="color: #000000">: The content category against which the device triggered.</span>
- **<span style="color: #000000">Policy</span>**<span style="color: #000000">: Active security policies.</span>
- **<span style="color: #000000">Source</span>**<span style="color: #000000">: The location of the device within the network infrastructure. For example, the device can be an </span>**<span style="color: #000000">on-prem</span>**<span style="color: #000000"> appliance or an </span>**<span style="color: #000000">endpoint</span>**<span style="color: #000000"> device. You can select which records to view by selecting or deselecting from among the options available. </span>
- **<span style="color: #000000">Show</span>**<span style="color: #000000">: Security and activity events can be filtered by choosing an option from the </span>**<span style="color: #000000">Show</span>**<span style="color: #000000"> drop-down menu. </span>

<span style="color: #000000">The </span>*<span style="color: #000000">Web Content </span>*<span style="color: #000000">table displays the following information by specific criteria. Select the applicable objects from the following column drop-down menus:</span>

- **<span style="color: #000000">DETECTED</span>**<span style="color: #000000">: The date the indicator was first detected. </span>
- **<span style="color: #000000">QUERY</span>**<span style="color: #000000">: Displays the domain that sent the DNS queries. You can view the Dossier record of a threat class or property by clickingthe view on Dossier icon </span><span style="color: #000000">associated with a record allows you to view the Dossier threat look-up record of a threat class or property for the selected record. On the Dossier threat look-up page, you can view the Dossier report details for additional information on the selected record.</span>
- **<span style="color: #000000">CATEGORY</span>**<span style="color: #000000">: The content category against which the device triggered.</span>
- **<span style="color: #000000">POLICY</span>**<span style="color: #000000">: The security policy against which the malicious hit triggered.</span>
- **<span style="color: #000000">ACTION</span>**<span style="color: #000000">: The configured action for the security rule. This can be </span>**<span style="color: #000000">Allow</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Redirect</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Block</span>**<span style="color: #000000">, or </span>**<span style="color: #000000">Log</span>**<span style="color: #000000">.</span>
- **<span style="color: #000000">DEVICE NAME</span>**<span style="color: #000000">: The name of the device.</span>**<span style="color: #000000">  </span>**
- **<span style="color: #000000">USER</span>**<span style="color: #000000">: The user that triggered the hit. For remote offices, the portal displays </span>**<span style="color: #000000">Unknown</span>**<span style="color: #000000"> for these users.</span>
- **DEVICE**<span style="color: #000000"> </span>**IP**<span style="color: #000000">: The</span><span style="color: #000000"> </span>**IP**<span style="color: #000000"> </span><span style="color: #000000">address of the</span><span style="color: #000000"> </span>**device**<span style="color: #000000"> </span><span style="color: #000000">responsible for the hit.</span>
  ***Export Records***
  Click **Export** to download a CSV file of report records. The maximum number of exported Web Content report records is **50,000**.