Prepare the safe path
- Only activity inside both the selected time range and the plan and profile retention windows can appear.
- If the plan cannot retain 30 days, Analytics defaults to the longest available range instead.
- Endpoint attribution requires Full logging. Anonymized history remains available only as privacy-protected aggregate activity.
1 Open Analytics and confirm the time range
Analytics defaults to 30 days on plans that retain it. Otherwise it selects the longest plan-supported range. Use Time range for 24h, 48h, 1w, 30d, or 90d; choices beyond the plan limit remain unavailable.
2 Confirm the report scope
The default All endpoints scope summarizes DNS queries, blocked requests, resolver processing, active endpoints, categories, and top domains inside the selected range.
3 Choose one endpoint
Use Report scope to select a direct device or Relay. QueryWarden refreshes the metric cards, traffic trend, block categories, and domain lists for that endpoint only.
4 Switch between Bar and Line
Bar is the default account view. Line plots total DNS queries and blocked requests over the same retention buckets. Changing the chart does not change the report data.
5 Compare endpoint lines
Return to All endpoints and choose the multi-line icon. Each current device or Relay receives its own query-volume line. Inspect a point for query and blocked totals, or use the legend to hide and restore individual lines.
6 Respect the privacy boundary
Anonymized events are shown only as Privacy-protected activity and are never assigned back to a device. Logging Off creates no retained endpoint history. These rules can make the sum of named endpoint lines lower than the account total.
Confirm the result
You can change the reporting window, move from the account overview to one endpoint, or compare endpoint traffic without changing DNS policy, stored retention, or resolver behavior.
Protect the account while you work
- Analytics is read-only and never exposes a private DNS endpoint URL.
- Do not publish screenshots containing real domains, endpoint names, or household and employee identities.
When the expected result does not appear
An endpoint report is empty while account totals exist.
Check the endpoint profile under Privacy. Anonymized activity cannot be attributed and logging may be Off.
Endpoint lines do not add up to the account total.
Look for the Privacy-protected activity line and retention notes. Anonymized events remain account-level by design.
A longer time range cannot be selected.
The account plan does not retain that window. Choose the longest enabled range or review the plan options.
The endpoint comparison icon is unavailable.
Select All endpoints first. Comparison is disabled while the report is scoped to one endpoint.