---
title: "Verifying RPZ Configuration"
canonical: "https://docs.infoblox.com/space/nios85/35979794/Verifying%20RPZ%20Configuration"
format: markdown
---
After you have set up and configured RPZs and RPZ rules, you can verify whether the RPZ zone transfers are functioning properly by doing the following:

- View the RPZ syslog messages, as described in *<span style="color: #0000ff">[Viewing](#VerifyingRPZConfiguration-bookmark3338)</span>*[ ](#VerifyingRPZConfiguration-bookmark3338)*<span style="color: #0000ff">[RPZ](#VerifyingRPZConfiguration-bookmark3338)</span>*[ ](#VerifyingRPZConfiguration-bookmark3338)*<span style="color: #0000ff">[in](#VerifyingRPZConfiguration-bookmark3338)</span>*[ ](#VerifyingRPZConfiguration-bookmark3338)*<span style="color: #0000ff">[the](#VerifyingRPZConfiguration-bookmark3338)</span>*[ ](#VerifyingRPZConfiguration-bookmark3338)*<span style="color: #0000ff">[Syslog](#VerifyingRPZConfiguration-bookmark3338)</span>*.
- Verify the last RPZ updates, as described in *<span style="color: #0000ff">[Viewing](#VerifyingRPZConfiguration-bookmark3341)</span>*[ ](#VerifyingRPZConfiguration-bookmark3341)*<span style="color: #0000ff">[the](#VerifyingRPZConfiguration-bookmark3341)</span>*[ ](#VerifyingRPZConfiguration-bookmark3341)*<span style="color: #0000ff">[Last](#VerifyingRPZConfiguration-bookmark3341)</span>*[ ](#VerifyingRPZConfiguration-bookmark3341)*<span style="color: #0000ff">[Updated](#VerifyingRPZConfiguration-bookmark3341)</span>*[ ](#VerifyingRPZConfiguration-bookmark3341)*<span style="color: #0000ff">[RPZs](#VerifyingRPZConfiguration-bookmark3341)</span>*.

The appliance also makes a syslog entry, when an RPZ zone refresh succeeds or fails and also sends an SNMP trap and an email notification, if configured. For information about setting SNMP and email notification, see *<span style="color: #0000ff">[Setting](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35385484/Configuring+SNMP#ConfiguringSNMP-bookmark2880)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35385484/Configuring+SNMP#ConfiguringSNMP-bookmark2880)*<span style="color: #0000ff">[SNMP](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35385484/Configuring+SNMP#ConfiguringSNMP-bookmark2880)</span>* *<span style="color: #0000ff">[and](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35385484/Configuring+SNMP#ConfiguringSNMP-bookmark2880)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35385484/Configuring+SNMP#ConfiguringSNMP-bookmark2880)*<span style="color: #0000ff">[Email](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35385484/Configuring+SNMP#ConfiguringSNMP-bookmark2880)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35385484/Configuring+SNMP#ConfiguringSNMP-bookmark2880)*<span style="color: #0000ff">[Notifications](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35385484/Configuring+SNMP#ConfiguringSNMP-bookmark2880)</span>*[.](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35385484/Configuring+SNMP#ConfiguringSNMP-bookmark2880)

# > Macro (anchor)

> Macro (anchor)

> Macro (anchor)

Viewing RPZ in the Syslog

To receive RPZ information in the syslog, make sure that you enable the RPZ option in the Logging tab of the Grid DNS Properties editor. For information about configuring logging properties, see *<span style="color: #0000ff">[Setting DNS Logging Categories](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35784616/Using+a+Syslog+Server#UsingaSyslogServer-bookmark2793)</span>*. Once the RPZ option is enabled, the appliance logs RPZ threats in CEF (Common Event Format) in the syslog. You can click the Action icon to view the RPZ threat details in the RPZ Threat Details viewer. For information about how to configure the syslog server, see <span style="color: #0000ff">[*Using a Syslog Server*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35784616)</span>.

Following is a sample RPZ threat message:

`2014-09-15T07:14:47-07:00 daemon info rpz:`  
`CEF:0|Infoblox|NIOS|6.12.0-252689|RPZ-QNAME |PASSTHRU|7|app=DNS dst=172.31.1.156`  
`src=10.120.20.69 spt=39503 view=_default qtype=A msg="rpz QNAME PASSTHRU rewrite`  
`passthru.com [ANY] via passthru.com.rpz_1.com`

Each log message contains the following information:

- The timestamp when the event happened in yyyy-mm-ddThh:mm:ss-00:00 format.
- **Infoblox|NIOS** **|x.x.x**: Indicates the Infoblox product, and x.x.x represents the NIOS version.
- The string following the NIOS version is a hard-coded constant. In this example, it is RPZ QNAME.
- The hard-coded constant is followed by mitigation action. In this example, it is PASSTHRU.
- The number following the mitigation action is the threat severity level. The following numbers indicate the severity levels:
  - **8** = **Critical**
  - **7** = **Major**
  - **6** = **Warning**
  - **4** = **Informational**
- **dst**: Destination IP address.
- **src**: Source IP address.
- **spt**: Source port.
- **view**: DNS view.
- **qtype**: Query type.
- **msg**: RPZ rule.

The syslog messages are optionally tagged according to the logging category configured in the external syslog servers. For more information, see *<span style="color: #0000ff">[Syslog](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35784616/Using+a+Syslog+Server#UsingaSyslogServer-bookmark2786)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35784616/Using+a+Syslog+Server#UsingaSyslogServer-bookmark2786)*<span style="color: #0000ff">[Message](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35784616/Using+a+Syslog+Server#UsingaSyslogServer-bookmark2786)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35784616/Using+a+Syslog+Server#UsingaSyslogServer-bookmark2786)*<span style="color: #0000ff">[Prefixes](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35784616/Using+a+Syslog+Server#UsingaSyslogServer-bookmark2786)</span>*.   
 To verify RPZ zone transfers:

1. Go to the **Administration** tab -> **Logs** tab -> **Syslog** tab.
2. Select **RPZ** **Incident** **Logs** from the **Quick** **Filter** drop-down list.
3. Review the syslog for zone transfer confirmation, as shown in *<span style="color: #0000ff">[Figure](#VerifyingRPZConfiguration-bookmark3340)</span>*[ ](#VerifyingRPZConfiguration-bookmark3340)*<span style="color: #0000ff">[42.5](#VerifyingRPZConfiguration-bookmark3340)</span>*.

  
 > Macro (anchor)

*Figure* 42.5 *The* *Syslog* *Viewer*

![image](media://6c8057ee-d0fa-4149-96af-b3ae798c4d26)

# > Macro (anchor)

> Macro (anchor)

Viewing the Last Updated RPZs

To view the last updated RPZs:

1. Go to the **Data** **Management** tab -> **DNS** tab -> **Response** **Policy** **Zones** tab.
2. Review the **Last** **Updated** column and confirm the time when an RPZ was last updated, as shown in *<span style="color: #0000ff">[Figure](#VerifyingRPZConfiguration-bookmark3342)</span>*[ ](#VerifyingRPZConfiguration-bookmark3342)*<span style="color: #0000ff">[42.6](#VerifyingRPZConfiguration-bookmark3342)</span>*.

---

**Note:** It may take up to 10 minutes before the updated information is displayed.

---

  
 > Macro (anchor)

*Figure* 42.6 *Last* *Updated* *RPZ*   
> Macro (inline-media-image)