ACTIVITY AND PRIVACY

Review and manage security incidents

Operations → Incidents is a tenant-scoped triage table for measured changes in retained DNS activity. It keeps the essential severity, detector, device or scope, status, last detection time, and occurrence count visible while detailed evidence remains behind View details.

Available now Account owners and authorized security operators
BEFORE YOU START

Prepare the safe path

  • An incident is evidence that a documented detector threshold was met; it is not proof of compromise.
  • Privacy and retention settings determine which hostnames and device attribution can be included.
  • Incident detection never creates a live DNS rule automatically.
  1. 1

    Start with the active workload

    Use the summary to see active and high-priority counts. The table initially includes every retained incident and sorts by the latest detection time.

  2. 2

    Search or narrow the table

    Search across incident names, detector types, devices, profiles, statuses, alert state, retained evidence, and eligible hostname samples. Type, Device / scope, Severity, and Status filters can be combined.

  3. 3

    Sort the operational view

    Choose a sortable column heading to order by severity, incident name, device or scope, status, last detection time, or occurrence count. Choose the same heading again to reverse direction.

  4. 4

    Open only the evidence you need

    View details shows the measurement window, last detection, occurrence count, alert delivery, scope, recorded evidence, representative retained hostnames, detector threshold, limitations, and privacy coverage.

  5. 5

    Record a response

    Acknowledge records that the incident is under review. Resolve closes the operational item without deleting its evidence. Reopen returns a resolved item to the active queue.

  6. 6

    Treat recommendations as a starting point

    Review suggestions do not change policy. When a Policy Lab option exists, it creates only a read-only simulation; live activation remains a separate deliberate action.

WHAT SUCCESS LOOKS LIKE

Confirm the result

You can find an incident quickly, understand why it was raised and what data supports it, then record its operational status without silently changing DNS protection.

SECURITY NOTES

Protect the account while you work

  • Do not share screenshots containing real hostnames, device names, household members, employees, or customer identities.
  • A generated-looking hostname, volume change, new-domain burst, NXDOMAIN pattern, or block-rate increase can have legitimate explanations. Investigate context before changing policy.
TROUBLESHOOTING

When the expected result does not appear

Search returns no incidents.

Clear the current filters and try a device name, detector type, status, or retained hostname. Privacy-protected evidence may not contain a hostname.

An account incident has no device.

The detector may be account-wide or the underlying activity may be anonymized. QueryWarden does not reconstruct device identity from private aggregates.

A recommendation cannot be activated from the incident.

This is intentional. Open the read-only Policy Lab simulation, inspect measured impact, and use the separate authorized activation workflow only if justified.

PRODUCT STATE

Capabilities used in this guide

Explainable security decisions · Available now