Using reverse DNS lookup

Prev Next

Use the NDR Reverse DNS Lookup function in the Event Table to find the domain name for a specific IP address.

Event Table Filters.png
To perform a reverse DNS lookup:

Note

When using the Filter tab, you must click the Apply button at the bottom left of the Filter tab each time you add or modify a filter. This applies the new or modified filter to your NDR search query.

  1. Click Main_menu.png and from INVESTIGATION, select Search.

  2. Click the Filters tab and create an HTTP filter to your packet search.

  3. Click Apply to add the filter to your search.

  4. Click the Add Component button at the bottom of the dashboard and select the Event Table widget.

  5. Click Add Component to save the widget to your dashboard.

  6. Click the search icon, next to the Query Bar, to run the search.

  7. From the Event Table, select an IP address field from the sourceIPv4Address or destinationIPv4Address column.

  8. Click the field drop-down menu and select Reverse DNS Lookup.