ACTIVITY AND PRIVACY

Compare account and endpoint analytics

Analytics opens with the retained account-wide bar chart and defaults to 30 days when the plan supports it. Time range can switch between 24 hours, 48 hours, 1 week, 30 days, and 90 days within the plan limit. Report scope can narrow the complete report to one device or Relay, while the chart controls can show account lines or compare every current endpoint on the same timeline.

Available now Account owners and authorized users reviewing DNS activity
BEFORE YOU START

Prepare the safe path

  • Only activity inside both the selected time range and the plan and profile retention windows can appear.
  • If the plan cannot retain 30 days, Analytics defaults to the longest available range instead.
  • Endpoint attribution requires Full logging. Anonymized history remains available only as privacy-protected aggregate activity.
  1. 1

    Open Analytics and confirm the time range

    Analytics defaults to 30 days on plans that retain it. Otherwise it selects the longest plan-supported range. Use Time range for 24h, 48h, 1w, 30d, or 90d; choices beyond the plan limit remain unavailable.

  2. 2

    Confirm the report scope

    The default All endpoints scope summarizes DNS queries, blocked requests, resolver processing, active endpoints, categories, and top domains inside the selected range.

  3. 3

    Choose one endpoint

    Use Report scope to select a direct device or Relay. QueryWarden refreshes the metric cards, traffic trend, block categories, and domain lists for that endpoint only.

  4. 4

    Switch between Bar and Line

    Bar is the default account view. Line plots total DNS queries and blocked requests over the same retention buckets. Changing the chart does not change the report data.

  5. 5

    Compare endpoint lines

    Return to All endpoints and choose the multi-line icon. Each current device or Relay receives its own query-volume line. Inspect a point for query and blocked totals, or use the legend to hide and restore individual lines.

  6. 6

    Respect the privacy boundary

    Anonymized events are shown only as Privacy-protected activity and are never assigned back to a device. Logging Off creates no retained endpoint history. These rules can make the sum of named endpoint lines lower than the account total.

WHAT SUCCESS LOOKS LIKE

Confirm the result

You can change the reporting window, move from the account overview to one endpoint, or compare endpoint traffic without changing DNS policy, stored retention, or resolver behavior.

SECURITY NOTES

Protect the account while you work

  • Analytics is read-only and never exposes a private DNS endpoint URL.
  • Do not publish screenshots containing real domains, endpoint names, or household and employee identities.
TROUBLESHOOTING

When the expected result does not appear

An endpoint report is empty while account totals exist.

Check the endpoint profile under Privacy. Anonymized activity cannot be attributed and logging may be Off.

Endpoint lines do not add up to the account total.

Look for the Privacy-protected activity line and retention notes. Anonymized events remain account-level by design.

A longer time range cannot be selected.

The account plan does not retain that window. Choose the longest enabled range or review the plan options.

The endpoint comparison icon is unavailable.

Select All endpoints first. Comparison is disabled while the report is scoped to one endpoint.

PRODUCT STATE

Capabilities used in this guide

DNS analytics · Available now