In case you need some ideas about how to make the logs better.
Allowed domains are green.
Blocked domains are red.
Not yet allowed domains could be: yellow.
Authoritative entries from dashboard: blue.
Hosts lookup could be: grey.
Users that are scanning through the logs to look for unblock requests could easily just go to the yellow ones and request them. It would help them differentiate between things that are permanently blocked versus things that could be unblocked.
There could be switches to mute every subtype of request.
If the current user is allowed to see all logs, there should be a quick switch at the top to just show “own logs”. Admins are spending the most amount of time of anyone looking at logs and a lot of it is just their own logs. So a quick switch to just look at their own would be very handy.
There should be an option per site to mute logs from devices that are on a no Internet policy. every lookup these devices makes is obviously blocked and there’s no good reason to see them.
There should be a list of devices per site that are always muted in the logs.
There should be an option to mute mDNS look ups. On a site with 30 printers, let’s say, those lookups can take up a lot of real estate.
There should be a quick switch at the top to temporarily show all the muted devices.
There could be an option in the domain log to click on a little icon next to a requester device and go straight to their traffic log, pre-filtered to show just that devices interactions.
Traffic log should have an option to show local source hostnames instead of IP addresses. Like the domain log. And if possible, a host name for the destination as well. A toggle for this would be nice. Would make it a lot easier to decipher who is reaching out to what.
I’m sure I’ll think of more if you need more.
Adam users please get out there and (up)vote!