How can I get my GMS/Analyzer "Web Activity" reports to show only User-visited domains?
03/26/2020 43 12560
How can I get my GMS Web Activity reports to show only User-visited domains, instead of long subdomains?
Example: I wish only to see the visited domains such as espn.com, amazon.com, rather than long subdomains such as hds.video-cdn.espn.com, s3-us-west-2-w.amazonaws.com, a32-203-64-189.deploy.static.akamaitechnologies.com, etc etc when my users visit a site.
When a server name is returned for a website, they are also being redirected to other sites that the content is actually served from. This information WILL be seen by your reports as it is served if the server is not already known.
However, the name resolution by DNS is not the acutal means by which a website was looked up if content filtering is in play. When using CFS, the name lookup was performed not merely by the ceritificate common name for HTTPS (without DPI-SSL), and by get request when using HTTP (or HTTPS with DPI-SSL). If this is available, the syslog information will have provided this for the connection.
If no server name was given for the IP address, The firewall will fallback to DNS resolution when providing the syslog to GMS (or netbios resolution, depending on your log configuration). Note that this must be done AT THE FIREWALL, and not in GMS, as based on the log > settings section.
Ensure name resolution is DISABLED on GMS itself, under Console > Reports > Summarizer > Public IP Hostname Resolution Configuration. This should only be provided by the firewall.
Also consider configuring DPI-SSL on your firewall so that any HTTPS connections that are relayed through a new server for some information within a service can be seen via a get request for that socket, rather than attempting to rely on reverse DNS resolution or a certificate common name.