The Top Identities report lists your organization's most active identities, based on DNS requests, over the selected time period.
- Navigate to Reporting > Additional Reports > Top Identities.
- Identity—The identity. Clicking an individual identity will bring you to the Identity Details for that identity.
Requests—The number of requests the identity sent for the selected time period.
Select a time frame to view the Top Identities report.
The report can be filtered by the last 24 hours, yesterday, the last 7 days, last 30 days, or a custom range within the last 30 days.
- Filter by response type. Select Allowed or Blocked. By default, nothing is selected, so all responses are shown.
- Choose the identity types to show. By default, none are selected, so all are shown.
You can also search for an identity by name, domain, or URL.
- Filter by security categories. By default, none are selected, so all are shown. For more information about security categories, see Manage Security Categories.
- Filter by content categories. By default, none are selected, so all are shown. For a complete list of content categories, see Manage Content Category Settings.
Each line in the report includes a menu displayed as three dots. Click this menu to reveal options for the selected identity:
- View Security Activity—Redirects you to the Security Activity report.
- View in Activity Search—Redirects you to the [Activity Search report](https://docs.umbrella.com/deployment-umbrella/v1.0.5/docs/the-activity-search-report.
- View in Activity Volume—Redirects you to the Activity Volume report.
Updated 3 days ago