Approved

Live Discover Query for all DNS requests in a time frame with process (ZTNA App discover)

Hi Team, Here is a Live Discover Query for all DNS requests in a particular time frame from a device. You can use % for all processes or search for a particular process.

-- DNS Lookups by Process
-- $$Start Time$$       DATE
-- $$End Time$$         DATE
-- $$Process Name$$     STRING (Use % as wildcard, for example mcs% )
SELECT DISTINCT
   sdj.name,
   spj.process_name
FROM
   sophos_dns_journal AS sdj
JOIN
   sophos_process_journal AS spj
ON
   sdj.sophos_pid = spj.sophos_pid
WHERE
   sdj.time > '$$Start Time$$' AND
   sdj.time < '$$End Time$$' AND
   lower(spj.process_name) LIKE (lower('$$Process Name$$'))
ORDER BY spj.process_name

This is a good approach to localize an unknown app for ZTNA as well. If you have a process that does not work, you can remotely look for all used DNS requests to allow them through.