Edge DNS reports

Edge DNS provides a secure, high-performance, scalable, and highly available edge service for authoritative DNS. Use the Edge DNS reports on ​Control Center​ to check service availability (uptime), monitor traffic on the service, analyze patterns for troubleshooting and threats, compile information for others, and forecast capacity.

You can access the reports from the REPORTS page. See How to use reports.

The next sections describe the data granularity, filters, graphic visualizations, and metrics associated with each report.

For additional information about these reports, see also Monitor and report on service, traffic, and threats in the Edge DNS user guide help.

Edge DNS Availability report

The Edge DNS Availability report tracks service availability (uptime) of the top-level DNS name servers for your selected contract and time frame up to 90 days.

Data granularity

This report returns up to 90 days of data.

Filters

  • Contracts. Each contract is assigned a set of top-level DNS name servers. Availability is calculated by looking at the uptime of the name servers for your contract.

Graphic visualization

  • Availability By Time. Graphic visualization displaying availability percentages for the selected time frame. This widget updates every 10 minutes. When viewing the report over longer time frames, availability can summarize across wider intervals (for example, every hour). Hover over the graph to see the percentage availability for a give date and time.

Metrics

  • Avg Availability %. Average availability percentage for the selected time frame.

  • Max Availability %. Maximum availability percentage for the selected time frame.

  • Min Availability %. Minimum availability percentage for the selected time frame.

Edge DNS report

This traffic report provides DNS hit counts and request rates for the selected zones and time frame up to 90 days.

Data granularity

This report returns up to 90 days of data.

Filters

  • Zone names. Names of the zones to report on.

Graphic visualizations and table

  • DNS Requests per Second. Graphic visualization displaying the rate of DNS hits per second. Hover over the graph to see Requests/Sec for a given Date/Time.

  • NXDOMAIN Responses/Sec. Graphic visualization displaying the rate, in seconds, of nonexistent domain (NXDOMAIN) responses during the specified time frame. Hover over the graph to see Responses/Sec for a given Date/Time.

  • Zone Summary. Table summarizing the total number of DNS requests per zone, the total number of NXDOMAIN responses, and the percentage of NXDOMAIN responses.

The graphic visualization and table widgets display data for the same time period to facilitate comparisons.

Metrics

  • Total DNS Hits. Total number of DNS hits (responses). This count includes Total NXDOMAIN Hits.

  • Peak Hits/Sec. Maximum (peak) DNS hits per second.

  • Total NXDOMAIN Hits. Total number of NXDOMAIN hits (responses).

  • Peak Hits/Sec. Maximum NXDOMAIN hits per second.

Edge DNS Today report

The Edge DNS Today report includes more detailed traffic data than the Edge DNS report, for the selected zones and time frame up to 14 days.

The report provides a heat map of query source locations by geographic region, as well as graphic visualizations and analytics of DNS requests.

Data granularity

This report returns up to 14 days of data.

Filters

  • Zone names. Names of the zones to report on.

Graphic visualizations and tables

  • Sources of Traffic by Region. Heat map displaying the sources of DNS requests by region.

  • Top Requests. Table summarizing the Sources of Traffic by Region heat map data. The table shows the top DNS requests by region and the associated number of requests.

  • DNS Requests per Second. Graphic visualization displaying the rate of DNS hits per second. Hover over the graph to see Requests/Sec for a give Date/Time.

  • NXDOMAIN Responses per Second. Graphic visualization displaying the nonexistent domain (NXDOMAIN) responses per second for the specified time frame. Hover over the graph to see Responses/Sec for a give Date/Time.

  • Zone Summary. Table summarizing the following metrics by zone: total number of DNS requests, total number of DNS requests that resulted in NXDOMAIN responses, and percentage of all DNS requests that resulted in NXDOMAIN responses.

Metrics

  • Total Requests. Total number of DNS requests.

  • Total NXDOMAIN Responses. Total number of NXDOMAIN responses.

  • NXDOMAIN Percent. NXDOMAIN responses as a percentage of all DNS hits.

  • Peak Requests/Sec. Maximum (peak) DNS hits per second.

  • Peak NXDOMAIN Responses/Sec. Maximum NXDOMAIN responses per second.

  • Total DNS Hits. Total number of DNS hits (responses). This count includes Total NXDOMAIN Hits.

  • Peak Hits/Sec. Maximum number of DNS hits per second.

  • Total NXDOMAIN Hits. Total number of NXDOMAIN hits.

  • Peak Hits/Sec. Maximum number of NXDOMAIN hits per second.

Edge DNS Zone Detail report

The Edge DNS Zone Detail report provides even more traffic data than the Edge DNS Today report for one selected zone and time frame up to 14 days.

The report provides a heat map of query source locations by geographic region, along with graphic visualizations and analytics of DNS requests. Additionally, the report provides hits per second over time, record-level counts, and top nonexistent domains (NXDOMAINs) for the selected time frame.

Record-level counts are helpful to learn about use at the label level. Top NXDOMAINs help characterize and understand a common attack vector known as random subdomain, where an attacker gains control over a subdomain of a target domain.

Data granularity

This report returns up to 14 days of data.

Filters

  • Zone name. Name of the zone to report on.

Graphic visualizations and tables

  • Sources of Traffic by Region. Heat map displaying query source locations by geographic region.

  • Top Requests. Table summarizing the Sources of Traffic by Region heat map data. The table shows the top DNS requests by region and the associated number of requests.

  • DNS Requests per Second. Graphic visualization displaying the rate of DNS requests per second. Hover over the graph to see Requests/Sec for a give Date/Time.

  • NXDOMAIN Responses per Second. Graphic visualization displaying the rate of NXDOMAIN responses per second. Hover over the graph to see Responses/Sec for a given Date/Time.

  • NXDOMAIN Summary. Table summarizing the NXDOMAIN Responses per Second graph data.

  • Requests by Record. Table displaying the total number of DNS requests for each record.

  • NXDOMAIN by Record. Table displaying the total number of NXDOMAIN responses for each record.

Metrics

  • Total Requests. Total DNS requests.

  • Total NXDOMAIN Responses. Total nonexistent domain (NXDOMAIN) responses.

  • NXDOMAIN Percent. Percentage of all DNS requests that resulted in NXDOMAIN responses.

  • Peak Requests/Sec. Maximum (peak) number of DNS requests per second.

  • Peak NXDOMAIN Responses/Sec. Maximum number of NXDOMAIN responses per second.

  • Total DNS hits. Total number of DNS hits (responses). This count includes Total NXDOMAIN Hits.

  • Peak Hits/Sec. Maximum DNS hits per second.

  • Total NXDOMAIN Hits. Total number of NXDOMAIN hits (responses).

  • Peak Hits/Sec. Maximum number of NXDOMAIN hits per second.

Edge DNS Threats Summary report

The Edge DNS Threat Summary report includes summary data about potential threats associated with the selected zones and time frame up to 90 days.

The report includes graphic visualizations of DNS requests per second and NXDOMAIN responses per second over time, a table summarizing the graph metrics, and a table listing per-zone metrics of potential threats. Additionally, the report includes a link to each zone's Edge DNS Threat Details report for further threat analysis.

Data granularity

This report returns up to 90 days of data.

Filters

  • Zone Names. Names of the zones to report on.

Graphic visualizations and tables

  • DNS Requests per Second. Graph displaying the number of DNS requests per second for the specified zones and time frame.

  • NXDOMAIN Responses per Second. Graph displaying the rate of nonexistent domain (NXDOMAIN) responses per second.

  • Zone Details. Table listing the number of DNS requests received per zone during the specified time frame, the number of requests that resulted in NXDOMAIN responses, and the percentage of DNS requests resulting in NXDOMAIN responses.

  • Threat Details. Table listing threat information per zone, which includes the start and end times of the threats, duration of the threats, percentage of DNS requests that resulted in NXDOMAIN responses, and the top country from which the threat requests were sent. Click the zone name in the table to open the Edge DNS Threat Details report. The report drills down to provide additional visualizations and analytics about the possible threat.

    If no threats are detected, the message NO DATA TO DISPLAY appears instead of the Threat Details table.

Metrics

  • Total Requests. Total number of DNS requests per second.

  • Total NXDOMAIN Responses. Total number of DNS requests that resulted in NXDOMAIN responses.

  • NXDOMAIN Percent. Total NXDOMAIN responses as a percentage of total DNS requests

  • Threats Identified. Total number of threats identified.

Edge DNS Threat Details report

The Edge DNS Threat Details report includes more data than the Edge DNS Threats Summary report about potential threats associated with one selected zone during the selected time frame up to 90 days.

For the selected zone threat, the report provides threat summary metrics including total DNS requests, total NXDOMAIN responses, NXDOMAIN percent, peak requests per second, and peak NXDOMAIN responses per second. Additionally, the report includes graphic visualizations of DNS requests per second and NXDOMAIN responses per second, heat maps and tables with DNS request counts and NXDOMAIN response counts by geographic region, and record-level counts of the most-requested existing DNS records and most-requested nonexistent DNS records.

Data granularity

This report returns up to 90 days of data.

Filters

  • Zone Name. Name of the zone to report on.

Graphic visualizations and tables

  • DNS Requests by Region. Heat map displaying the DNS requests for the selected zone by geographic region.

  • DNS Requests by Region. Table summarizing the data in the DNS Requests by Region heat map.

  • NXDOMAIN Responses by Region. Heat map displaying the number of nonexistent domain (NXDOMAIN) responses for the selected zone in the selected time period.

  • NXDOMAIN Responses by Region. Table summarizing the data in the NXDOMAIN Responses by Region heat map.

  • Most Requested Existing DNS Records. Table listing the most-requested existing DNS records and the total request count.

  • Most Requested Nonexistent DNS Records (1 Day Granularity). Table listing the most-requested nonexistent DNS records for the entire day the threat occurred, rather than just during the threat duration time. For example, if the threat spans from 07/13/2023 13:45 UTC to 07/13/2023 14:00 UTC, the table data would cover the period from 07/13/2023 00:00 to 07/13/2023 23:59 UTC.

Metrics

  • Total Requests. Total number of DNS requests.

  • Total NXDOMAIN Responses. Total number of DNS requests that resulted in nonexistent domain responses.

  • NXDOMAIN Percent. Total NXDOMAIN responses as a percentage of total DNS requests.

  • Peak Requests/sec. Maximum (peak) DNS hits per second.

  • Peak NXDOMAIN Responses/sec. Maximum (peak) nonexistent domain hits per second.

Security Analytics: Security Summary report

The Security Summary report is a security analytics report that provides data on DNS traffic, NXDOMAIN responses, and based on configured thresholds, NXDOMAIN spikes in your selected zone or zones. This report also correlates data to show information on DNS traffic across these delivery and security products: Prolexic, App & API Protector, and Web Security.

Data granularity

This report returns up to 14 days of data.

Filters

  • Zone names. Names of the zones to report on. You can select one or more zones.
  • Security configuration. Security configuration for App & API Protector.
  • Policy domain names. Unique name or tag in a string format that’s used by administrators to refer to policies, rules, entitlements, or configurations. The policy domain name may contain a contract name, product name, or other data.

Graphic visualization and tables

  • Edge DNS Traffic. Graph that shows all DNS requests, requests with NXDOMAIN responses, and requests that do not have NXDOMAIN responses.
  • Edge Traffic. Graph that shows Edge traffic in bits per second (bps) and packets per second (pps).
  • Prolexic Pre-Migration Traffic. Graph that shows Prolexic traffic before it reaches an ​Akamai​ scrubbing center in bps and pps.
  • App & API Protector Traffic. Graph that shows the number of detected denial-of-service (DoS) attacks, web application firewall (WAF) attacks, and bots.
  • NXDOMAIN Spikes. Table that shows NXDOMAIN spikes within a specific zone. The table shows the start and end time of the spike, the duration of the event, the total number of DNS requests, the total number of NXDOMAINs, and the country where the most NXDOMAIN spikes occurred.
  • Prolexic Events. Table that shows data on Prolexic events. The table shows the type of event, the severity level of the event, date and time the threat was first and last detected, the configuration where it applies, summary or description of the event, and the affected IP addresses. If the event is considered part of an attack, you can click the Attack event type to view more information in the Routed Events page of Security Center.
  • Web Security Alerts. Table that shows Web Security Alerts. Table shows priority of the alert, name of alert, time when the alert started and ended, filters that were applied, and information on how the alert was triggered. For recent alerts, you can click the alert name to go to the Web Security Analytics page in Security Center to view more information about the alert.

Metrics

  • DNS Requests. Total number of DNS requests.
  • NXDOMAIN Responses. Total number of NXDOMAIN responses.
  • NXDOMAIN Spikes. Number of NXDOMAIN spikes based on configured thresholds. To configure NXDOMAIN spike thresholds, see Configure NXDOMAIN spike thresholds.
    You can click a zone name to view the Security Analytics: NXDOMAIN Spike Details report.
  • Prolexic Events. If your organization uses Prolexic, this is the number of Prolexic events.
  • Web Security Alerts. If your organization uses Web Security, this is the number of Web Security alerts.

Security Analytics: Edge DNS Summary report

The Edge DNS Summary report is a security analytics report that provides information on DNS requests and NXDOMAIN responses. This report shows the total number of DNS responses, NXDOMAIN spikes, and the percentage of traffic that contained NXDOMAIN responses. It also shows the countries where the most requests and NXDOMAIN responses occurred.

Data granularity

This report returns up to 14 days of data.

Filters

  • Zone names. Names of the zones to report on. You can select one or more zones.

Graphic visualization and tables

  • Edge DNS Traffic. Graph that shows all DNS requests, requests with NXDOMAIN responses, and requests that do not have NXDOMAIN responses.
  • Edge DNS Zones. Table that lists total number of DNS requests, total number of NXDOMAINs, and the percent of DNS traffic that contained NXDOMAINs.
  • DNS Requests by Country. Heat map that shows DNS requests based on geographic region.
  • NXDOMAIN Responses by Country. Heat map that shows NXDOMAIN responses based on geographic region.
  • DNS Requests By Country. Table with data that corresponds to the DNS Requests by Country and NXDOMAIN Responses by Country maps. The table lists the total number of DNS requests and NXDOMAIN responses by country. By default, data is in descending order for DNS requests.
  • NXDOMAIN Spikes. Number of NXDOMAIN spikes based on the configured thresholds. To configure NXDOMAIN spike threshold, see Configure NXDOMAIN spike thresholds.
    You can click a zone name to view the Security Analytics: NXDOMAIN Spike Details report.

Metrics

  • Total Requests. Total number of DNS requests.
  • Total NXDOMAIN Responses. Total number of NXDOMAIN responses.
  • NXDOMAIN Percent. NXDOMAIN responses as a percentage of all DNS hits.
  • NXDOMAIN Spikes. Number of NXDOMAIN spikes based on configured thresholds. To configure NXDOMAIN spike thresholds, see Configure NXDOMAIN spike thresholds.

Security Analytics: Edge DNS Zone Details report

The Edge DNS Details report is a security analytics report that shows data on DNS traffic, NXDOMAIN responses, and based on configured thresholds, NXDOMAIN spikes in your selected zone or zones. This report shows the countries where most requests and NXDOMAIN responses occurred.

Data granularity

This report returns up to 14 days of data.

Filters

  • Zone names. Names of the zones to report on. You can select one or more zones.

Graphic visualization and tables

  • Edge DNS Traffic. Graph that shows all DNS requests, requests with NXDOMAIN responses, and requests that do not have NXDOMAIN responses.
  • Edge DNS Zones. Table that lists total number of DNS requests, total number of NXDOMAINs, and the percent of DNS traffic that contained NXDOMAINs.
  • DNS Requests by Country. Heat map that shows DNS requests based on geographic region.
  • NXDOMAIN Responses by Country. Heat map that shows NXDOMAIN responses based on geographic region.
  • DNS Requests By Country. Table with data that corresponds to the DNS Requests by Country and NXDOMAIN Responses by Country maps. The table lists the total number of DNS requests and NXDOMAIN responses by country. By default, data is in descending order for DNS requests.
  • NXDOMAIN Spikes. Number of NXDOMAIN spikes based on your configured thresholds. To configure NXDOMAIN spike thresholds, see Configure NXDOMAIN spike thresholds.
    You can click a zone name to view the Security Analytics: NXDOMAIN Spike Details report.

Metrics

  • Total Requests. Total number of DNS requests.
  • Total NXDOMAIN Responses. Total number of NXDOMAIN responses.
  • NXDOMAIN Percent. NXDOMAIN responses as a percentage of all DNS hits.
  • NXDOMAIN Spikes. Number of NXDOMAIN spikes based on configured thresholds.
    To configure NXDOMAIN spike threshold, see Configure NXDOMAIN spike thresholds.

Security Analytics: NXDOMAIN Spike Details report

The NXDOMAIN Spike Details report is a security analytics report that provides additional information on NXDOMAIN spikes. When you click a zone name in the Security Analytics, Edge DNS Summary, and Edge DNS Details reports, the NXDOMAIN Spike Details report appears.

Data granularity

This report returns up to 14 days of data.

Filters

  • Zone names. Names of the zones to report on. You can select one or more zones.

Graphic visualization and tables

  • Edge DNS Traffic. Graph that shows all DNS requests, requests with NXDOMAIN responses, and requests that do not have NXDOMAIN responses.
  • DNS Requests by Country. Heat map that shows DNS requests based on geographic region.
  • NXDOMAIN Responses by Country. Heat map that shows NXDOMAIN responses requests based on geographic region.
  • DNS Requests By Country. Table with data that corresponds to the DNS Requests by Country and NXDOMAIN Responses by Country maps. The table lists the total number of DNS requests and NXDOMAINs by country. By default, data is in descending order based on the number of DNS requests.
  • Most Requested Existing DNS Records. Shows the domain that’s most requested and the total number of requests made to those domains.
  • Most Requested Nonexisting DNS records (Last Day). Shows the most requested NXDOMAIN records and the total number of NXDOMAIN responses from the last 24 hours.

Metrics

  • Total Requests. Total number of DNS requests.
  • Total NXDOMAIN Responses. Total number of NXDOMAIN responses.
  • NXDOMAIN Percent. NXDOMAIN responses as a percentage of all DNS hits.
  • Peak Requests/Sec. Maximum (peak) DNS hits per second.
  • Peak NXDOMAIN Responses/Sec. Maximum (peak) NXDOMAIN response per second.