Overview
The DNS Filter integration enables ThreatAware to collect DNS security and filtering data from your DNS Filter environment, providing visibility into DNS security posture and web filtering policies.Connection Method: API
Setup Time: 10 minutes
Access Required: DNS Filter Administrator account
Data collected
The DNS Filter integration provides:- DNS filtering policy data
- Blocked DNS queries and threats
- DNS security events
- Web filtering logs
- Threat intelligence data
Use cases
DNS Security Monitoring
Monitor DNS-based threats and blocked malicious domains
Filtering Policy Validation
Verify DNS filtering policies are enforced across devices
Threat Detection
Detect DNS-based threats and suspicious domain access attempts
Compliance Reporting
Generate reports showing DNS security coverage and incidents
Setup instructions
1
Access DNSFilter Dashboard
Log in to the DNSFilter Dashboard using an account with administrator privileges.
2
Navigate to API Settings
In the DNSFilter console:
- Click on Settings in the main menu
- Select API Access from the settings options
- This section displays your API keys and allows you to manage API access
3
Generate API Key
In the API Access section:
- Click Generate API Key
- A new API key will be created for you
- Configure the API key with the required permissions:
- Typically Read-only access for monitoring is sufficient
- Select only the necessary permissions for ThreatAware
- Copy the generated API Key for use in ThreatAware
Only grant the minimum permissions necessary for ThreatAware to function
4
Configure in ThreatAware
Complete the integration setup in ThreatAware:
- Open ThreatAware and navigate to Settings > Integrations
- Search for and select DNSFilter
- Enter the required credential:
- API Key: The key generated in step 3
- Click Connect to establish the integration
5
Verify Connection
After connecting:
- Check that the Integration Status shows as Active
- Verify that DNS filtering data begins appearing in ThreatAware within 5-10 minutes
- Check the last sync timestamp
Required credentials
API Key
API Key
Field Name: DNSFilter API Key
Type: Password (encrypted)
Description: The API key generated in DNSFilter for ThreatAware integrationThis key provides access to DNS filtering and security data from DNSFilter.
Verification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings > Integrations in ThreatAware
- Confirm DNSFilter shows Active status
- Check the last sync timestamp
-
Verify Data Collection
- Wait 5-10 minutes for the initial data poll
- Check for DNS filtering and security data in ThreatAware
- Verify the data matches what you see in DNSFilter
-
Test Queries
- Create a test query to filter DNS security events
- Verify the filtering policy data matches your expectations
Troubleshooting
Invalid API Key Error
Invalid API Key Error
Symptoms: Integration status shows authentication failureSolutions:
- Verify the API Key is correct and was copied without extra spaces
- Ensure the API key has not been revoked in DNSFilter
- Check that your DNSFilter account still has administrator privileges
- Confirm the API key has the necessary permissions
- Generate a new API key if needed
Permission Issues
Permission Issues
Symptoms: Connection succeeds but no DNS filtering data appearsSolutions:
- Verify the API key has read permissions to DNS filtering data
- Check the DNSFilter API Documentation for required permissions
- Ensure the API key grants access to all required data types
- Review the permissions assigned to the API key in DNSFilter
- Recreate the API key with appropriate permissions if needed
Connection Timeout
Connection Timeout
Symptoms: Integration fails to connect or times outSolutions:
- Verify the DNSFilter dashboard is accessible and online
- Check firewall rules allow outbound HTTPS (443) to DNSFilter
- Test the DNSFilter URL in a browser to ensure connectivity
- Verify your internet connection is stable
- Try connecting again after waiting a few minutes
No Data After 10 Minutes
No Data After 10 Minutes
Symptoms: Integration shows active but no DNS filtering data appearsSolutions:
- Verify there is DNS filtering data in DNSFilter to collect
- Check that DNS filtering is actively processing traffic
- Confirm the API key has visibility to DNS events and logs
- Ensure devices are using DNSFilter for DNS resolution
- Wait up to 30 minutes for initial data sync to complete
- Review ThreatAware integration logs for errors
API Rate Limiting
API Rate Limiting
Symptoms: Integration works initially but stops syncing dataSolutions:
- Check DNSFilter for API rate limits
- Verify the API key is not hitting usage limits
- Wait for rate limits to reset before retrying
- Contact DNSFilter support about increasing rate limits if needed
- Optimize query patterns if possible to reduce API calls
Additional resources
DNSFilter API Documentation
Official DNSFilter API documentation for detailed API information
ThreatAware Support
Contact ThreatAware support for integration assistance