Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ismailurek2
New Contributor III

DNS logs show different app names

Hello,

 

In the firewall logs, different app names appear while DNS is expected to be seen as application in internet-directed DNS traffic, what is the reason for this? Can you give information about the subject? 

 

Best Regards,

İsmail Ürek

5 REPLIES 5
AEK
SuperUser
SuperUser

Hi Ismail

Can you share a screenshot?

AEK
AEK
ismailurek2
New Contributor III

Hi @AEK,

As seen in the image, there are apps such as “Yahoo.Mail” and “Google Translate”.

image.png

 

Best Regards,

İsmail Ürek

AEK

You are right, I can see the same in my firewall logs. I also see that Googlt.Traslate app signature uses DNS UDP 53, just like regular DNS query. I guess this some DNS queries that are sent to 8.8.8.8 (google) are assimilated to Google.Translate application.

AEK
AEK
ismailurek2
New Contributor III

Hi @AEK ,

 

How can I get more precise information on the subject? How can I prevent this from showing up in the logs?

 

Best Regards,

İsmail Ürek

AEK

Hi Ismail

This is just my deduction according to what I see in the logs, I don't have further information.

Hope some more experienced member can give a more precise answer.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors