Filtering Analytics
Monitor DNS queries and blocks across your devices, with top domains, block reasons, and a log of recent DNS events.
Filtering Analytics reports the DNS activity that Twingate resolves for your devices. It is in the Admin Console under Internet Security > Secure DNS.
To configure what DNS filtering blocks, see DNS Filtering.
Controls
The controls at the top of the tab apply to each component in the tab: the DNS filtering profile to limit the data to, and a time range of 7, 30, or 90 days.
Queries
The Queries chart summarizes DNS filtering activity over the selected time range: the total number of DNS queries, the number of blocked queries, and the percentage of queries that were blocked, plus a chart plotting both totals over time.
Top Block Reasons
This list ranks block reasons by the number of blocked queries in the selected time range, with a colored segmented bar showing each reason’s share of total blocks. Each reason is a specific denylist entry or DNS filtering rule, for example a security category like Google Safe Browsing or Typosquatting, a content category, or a privacy protection rule like Block Disguised Third-Party Trackers.
Top Domains
This list ranks domains by DNS request attempts in the selected time range. Toggle between Resolved and Blocked to switch between the top domains that resolved successfully and the top domains that were blocked. Each row shows the domain and its attempt count. Select Show More Results to see additional domains beyond the initial list.
Select the dropdown next to the heading and choose Top Devices to rank devices instead of domains, using the same Resolved/Blocked toggle and attempt counts.
Recent DNS Activity
Recent DNS activity shows a log of recent DNS filtering events. Filter the log to show all activity, which includes allowed and blocked domains, or just blocked domains. The search box matches domain names and applies within the selected filter, so you can search blocked events only. Select an event to see more details, including the device’s hostname and IP address, the filtering profile used, and, if a domain was blocked, the reason it was blocked.
Signed out device analytics
Devices can still use DNS filtering, even if a user is signed out, if they’ve been configured to run DNS filtering all of the time. If a user is signed out, their DNS filtering logs will show one of three things:
- If the device has never signed into Twingate, its hostname.
- If the device has signed into Twingate and only one user has ever used that device, the Twingate device name.
- If the device has signed into Twingate and been used by multiple users (e.g. a multi-user device or a laptop that was used by a former colleague), the name of the most recently signed in Twingate device.
Older Client versions
Client versions before macOS 2024.311 or Windows 2024.351 will show more generic device information when the user is signed out. In particular, you may see “No hostname” or “No device”. Upgrade your users’ Clients to see the hostname in the DNS filtering event feed.
Last updated