Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
daveywavey
New Contributor

DNS QUERY Cookbook question

Hello I followed the link below and got it to work, my question is how can I see more results? I was able to expand the results to 500, is there a way to make it more than 500?

 

http://cookbook.fortinet.com/logging-dns-domain-lookups/

 

Thanks,

David

Forti OS 4.0: FLG_100B-v400-build0705 (4.3.7) FWF_80CM-v400-build0665 (4.3.15) Forti OS 5.0: FWF_90D-v500-build0228 (5.0.3)
Forti OS 4.0: FLG_100B-v400-build0705 (4.3.7) FWF_80CM-v400-build0665 (4.3.15) Forti OS 5.0: FWF_90D-v500-build0228 (5.0.3)
5 REPLIES 5
awasfi_FTNT
Staff
Staff

Hello,

 

I believe you already added the dataset to a chart before using it on the report.

So you can edit the chart used by this report and set "Show Top" to "0" to show all results.

 

The device set by default to show 10,000 row per report:

# config system report setting

# get

max-table-rows      : 10000 report-priority     : low week-start          : sun

 

Regards,

daveywavey

Tried the above still shows only 500 results in the report.

last result below.

 

500 custom: DNS QUERY, dns_query=forum.fortinet.com; 14
Forti OS 4.0: FLG_100B-v400-build0705 (4.3.7) FWF_80CM-v400-build0665 (4.3.15) Forti OS 5.0: FWF_90D-v500-build0228 (5.0.3)
Forti OS 4.0: FLG_100B-v400-build0705 (4.3.7) FWF_80CM-v400-build0665 (4.3.15) Forti OS 5.0: FWF_90D-v500-build0228 (5.0.3)
awasfi_FTNT

It works for me on FortiAnalyzer v5.2.2.

Not sure about FortiAnalyzer v4.3, I think You need to edit the chart and input the value under the section "Only Show First" in the Data Bindings.  You may try "0" or something like 50000.

daveywavey

Hello I am using 5.2.5 and I tried the change in the Chart section and that fixed it thanks.

 

Might be worth adding that to the Cookbook for others.

D

Forti OS 4.0: FLG_100B-v400-build0705 (4.3.7) FWF_80CM-v400-build0665 (4.3.15) Forti OS 5.0: FWF_90D-v500-build0228 (5.0.3)
Forti OS 4.0: FLG_100B-v400-build0705 (4.3.7) FWF_80CM-v400-build0665 (4.3.15) Forti OS 5.0: FWF_90D-v500-build0228 (5.0.3)
daveywavey

Is there a way to add source IP to DNS Query dataset?

Below is from the cookbook entry

 

 

select msg, sum(totalnum) as totalnum from ###(select ipstr(srcip), msg, count(*) as totalnum from $log where $filter-exclude-var group by srcip, msg order by totalnum desc)### t where $filter-var-only and msg is not null group by msg order by totalnum desc

 

Thanks

Forti OS 4.0: FLG_100B-v400-build0705 (4.3.7) FWF_80CM-v400-build0665 (4.3.15) Forti OS 5.0: FWF_90D-v500-build0228 (5.0.3)
Forti OS 4.0: FLG_100B-v400-build0705 (4.3.7) FWF_80CM-v400-build0665 (4.3.15) Forti OS 5.0: FWF_90D-v500-build0228 (5.0.3)
Labels
Top Kudoed Authors