<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filter by DNS query the DNS requests in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/224986#M64524</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/62075"&gt;@CarlosDias&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You mean that, you want to search among the logs for eg.: nasa.org?&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
    <pubDate>Thu, 29 Aug 2024 16:09:59 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2024-08-29T16:09:59Z</dc:date>
    <item>
      <title>Filter by DNS query the DNS requests</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/224979#M64523</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;On the security logs on the Manager, how can I filter on DNS requests, the logs that have a specific DNS_query without opening line by line and see the DNS_query field ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 13:54:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/224979#M64523</guid>
      <dc:creator>CarlosDias</dc:creator>
      <dc:date>2024-08-29T13:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: Filter by DNS query the DNS requests</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/224986#M64524</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/62075"&gt;@CarlosDias&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You mean that, you want to search among the logs for eg.: nasa.org?&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 16:09:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/224986#M64524</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-29T16:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Filter by DNS query the DNS requests</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/224992#M64525</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/62075"&gt;@CarlosDias&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I checked in a working cluster. &lt;STRONG&gt;Here, the APPL and URLF blade are switched on.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;When I type a simple URL, the relevant results are shown in the log.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 16:29:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/224992#M64525</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-29T16:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: Filter by DNS query the DNS requests</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/224993#M64526</link>
      <description>&lt;P&gt;Same here, works in my R81.20 and R82 lab.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 16:33:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/224993#M64526</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T16:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: Filter by DNS query the DNS requests</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/225101#M64527</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;No that is not what I mean. That way I can find traffic that goes to a specific url or domain.&lt;/P&gt;&lt;P&gt;What I want is on a DNS packet sent to the DNS server I could filter the DNS_query field.&lt;/P&gt;&lt;P&gt;If you open a DNS packet log on the checkpoint you can see a field called DNS_query, where you can see what url it is asking to the DNS server. I am not able to filter that. The only solution is to open this dns traffic logs, one by one.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 08:40:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/225101#M64527</guid>
      <dc:creator>CarlosDias</dc:creator>
      <dc:date>2024-08-30T08:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: Filter by DNS query the DNS requests</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/225110#M64528</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dns.jpg" style="width: 820px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27445iE968650258559C53/image-size/large?v=v2&amp;amp;px=999" role="button" title="dns.jpg" alt="dns.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Btw is the version you still run is supported? I don't recall it is possible to see this in supported versions&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 10:44:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/225110#M64528</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-30T10:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Filter by DNS query the DNS requests</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/225111#M64529</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am running R81.10, which I thinks its still supported.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 10:46:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/225111#M64529</guid>
      <dc:creator>CarlosDias</dc:creator>
      <dc:date>2024-08-30T10:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Filter by DNS query the DNS requests</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/225112#M64530</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/62075"&gt;@CarlosDias&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If its field is not indexed, you&amp;nbsp; can'T search for it with regular expression.&lt;/P&gt;
&lt;P&gt;What is the most painful for me, the NAT field is te same.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 11:15:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/225112#M64530</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-30T11:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: Filter by DNS query the DNS requests</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/273681#M104192</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have version R82. How can I make the "dns_query" field appear in the domain-udp query logs? I tried the solutions from sk116694 and sk183647 without success, but it works in R81.20.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 07:46:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/273681#M104192</guid>
      <dc:creator>PA</dc:creator>
      <dc:date>2026-03-18T07:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: Filter by DNS query the DNS requests</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/273686#M104194</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have version R82. How can I make the "dns_query" field appear in the domain-udp query logs? I tried the solutions from sk116694 and sk183647 without success, but it works in R81.20.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 08:41:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filter-by-DNS-query-the-DNS-requests/m-p/273686#M104194</guid>
      <dc:creator>PA</dc:creator>
      <dc:date>2026-03-18T08:41:47Z</dc:date>
    </item>
  </channel>
</rss>

