To disable DNS network event capture for all of your host endpoints:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
From the Policies table, select the Agent Default Policy and click the policy link to access the Edit Policy page.
Select the Real-Time Indicator Detection tab.
.png)
In the Events section, toggle the Capture DNS Events ON/OFF switch to OFF.
.png)
Click Save.
To disable DNS network event capture for selected host sets:
Note
If you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
From the Policies table, click the link for the custom policy you want to modify.
Select the Real-Time Indicator Detection tab.
.png)
In the Events section, toggle the Capture DNS Events ON/OFF switch to OFF.
.png)
Click Save.