diff --git a/i18n/cs/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/cs/docusaurus-plugin-content-docs/current/general/dns-providers.md index 834de5129..6b98c9e6e 100644 --- a/i18n/cs/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/cs/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor je bezplatná alternativní DNS služba Hurri | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Přidat do AdGuardu](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Přidat do AdGuardu](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) poskytuje veřejně přístupné DNS s minimalizací QNAME, koncové body se nacházejí v Německu, Singapuru, Švédsku, Velké Británii a Spojených státech (New York a dallas). - -#### Bez filtrování - -| Protokol | Adresa | | -| -------------- | ----------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Přidat do AdGuardu](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Přidat do AdGuardu](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Blokování reklam - -| Protokol | Adresa | | -| -------------- | ------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Přidat do AdGuardu](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Přidat do AdGuardu](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Blokování reklam + malwaru - -| Protokol | Adresa | | -| -------------- | ---------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Přidat do AdGuardu](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Přidat do AdGuardu](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Blokování reklam + malwaru + sociálních médií - -| Protokol | Adresa | | -| -------------- | -------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Přidat do AdGuardu](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Přidat do AdGuardu](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Blokování reklam + malwaru + stránek pro dospělé + hazardních her - -| Protokol | Adresa | | -| -------------- | ------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Přidat do AdGuardu](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Přidat do AdGuardu](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Blokování reklam + malwaru + stránek pro dospělé + sociálních médií - -| Protokol | Adresa | | -| -------------- | --------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Přidat do AdGuardu](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Přidat do AdGuardu](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) je anycast systém filtrování internetu, který chrání děti před nevhodnými webovými stránkami a zneužitelným obsahem. @@ -611,7 +565,7 @@ Obvyklé servery DNS, které poskytují ochranu před krádeží identity a spyw #### Nezabezpečený -Nezabezpečené servery DNS neposkytují žádné zabezpečené seznamy zakázaných, DNSSEC, nebo EDNS Client-Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protokol | Adresa | | | -------------- | --------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | @@ -719,13 +673,13 @@ Blokuje reklamy a obtěžující weby. | --------- | ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | DNS, IPv4 | `114.114.114.114` a `114.114.115.115` | [Přidat do AdGuardu](adguard:add_dns_server?address=114.114.114.114&name=114DNS), [Přidat do AdGuard VPN](adguardvpn:add_dns_server?address=114.114.114.114&name=114DNS) | -#### Safe +#### Bezpečný -Blocks phishing, malicious and other unsafe websites. +Blokuje krádež identity, škodlivé a další nebezpečné weby. -| Protokol | Adresa | | -| --------- | --------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS, IPv4 | `114.114.114.119` and `114.114.115.119` | [Add to AdGuard](adguard:add_dns_server?address=114.114.114.119&name=114DNS), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=114.114.114.119&name=114DNS) | +| Protokol | Adresa | | +| --------- | ------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| DNS, IPv4 | `114.114.114.119` a `114.114.115.119` | [Add to AdGuard](adguard:add_dns_server?address=114.114.114.119&name=114DNS), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=114.114.114.119&name=114DNS) | #### Family @@ -1063,7 +1017,7 @@ In *Basic* mode, there is no traffic filtering. | DNS-over-HTTPS | `https://common.dot.dns.yandex.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://common.dot.dns.yandex.net/dns-query&name=yandex.doh), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://common.dot.dns.yandex.net/dns-query&name=yandex.doh) | | DNS-over-TLS | `tls://common.dot.dns.yandex.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://common.dot.dns.yandex.net&name=yandex.dot), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://common.dot.dns.yandex.net&name=yandex.dot) | -#### Safe +#### Bezpečný In *Safe* mode, protection from infected and fraudulent sites is provided. diff --git a/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index 50c1c9f2b..b054ab94d 100644 --- a/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,48 +3,58 @@ title: Rodičovská ochrana sidebar_position: 5 --- -## Co to je +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. -Rodičovská ochrana je soubor nastavení, který umožňuje přizpůsobit přístup k určitým webovým stránkám s citlivým obsahem. Pomocí této funkce můžete dětem omezit přístup na stránky pro dospělé, přizpůsobit vyhledávací dotazy, zablokovat používání oblíbených služeb a další. +## How to set it up -## Jak to nastavit +You can flexibly configure all features on your servers, including the parental control feature. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. -Na serverech můžete flexibilně konfigurovat všechny funkce, včetně funkce rodičovské ochrany. [V příslušném článku](private-dns/server-and-settings/server-and-settings.md) se můžete seznámit s tím, co je to server v AdGuard DNS, a dozvědět se, jak vytvořit různé servery s různými sadami nastavení. +Then, go to the settings of the selected server and enable the required configurations. -Poté přejděte do nastavení vybraného serveru a povolte požadované konfigurace. +### Block adult websites -### Blokování webových stránek pro dospělé - -Blokuje webové stránky s nevhodným obsahem a obsahem pro dospělé. +Blocks websites with inappropriate and adult content. ![Blocked website \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) -### Bezpečné vyhledávání +### Safe search + +Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -Odstraňuje nevhodné výsledky ze služeb Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave a Ecosia. +### YouTube restricted mode -![Safe search \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) +Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -### Omezený režim YouTube +### Blocked services and websites -Odstraňuje možnost prohlížet a přidávat komentáře pod videa a komunikovat s obsahem 18+ na YouTube. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. -![Restricted mode \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) +![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) -### Blokované služby a weby +### Block websites by category -AdGuard DNS blokuje přístup k oblíbeným službám jedním kliknutím. Je to užitečné, pokud nechcete, aby připojená zařízení navštěvovala například Instagram a YouTube. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. -![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) + +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: -### Blokovat weby podle kategorie +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. -Tato funkce vám umožňuje omezit přístup k určitým kategoriím webových stránek výběrem z více než 20 kategorií, včetně _Obsahu pro dospělé_, _Her_, _Bankovnictví_ a _Komunikace_. Pokud například zablokujete weby obsahující informace o alkoholu, tabáku nebo drogách, vybrané zařízení již nebude moci otevírat stránky spadající do těchto kategorií. +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### Nastavení času vypnutí +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -Povolí rodičovskou kontrolu ve vybraných dnech se zadaným časovým intervalem. Například jste svému dítěti povolili sledovat videa na YouTube pouze do 23:00 ve všední dny. O víkendech však tento přístup není omezen. Přizpůsobte si rozvrh podle svých představ a zablokujte přístup na vybrané stránky v požadovaných hodinách. +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![Schedule \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index 3f856a974..3982a3d41 100644 --- a/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ Ty se dále dělí na podkategorie: - **CDN**: požadavek připojený k síti CDN (Content Delivery Network), celosvětové síti proxy serverů, která urychluje doručování obsahu koncovým uživatelům - **Další** -### Nejaktivnější společnosti +## Nejaktivnější společnosti V této tabulce zobrazujeme nejen názvy nejnavštěvovanějších nebo nejčastěji blokovaných společností, ale také informace o tom, z jakých domén se o ně žádá nebo které domény jsou nejvíce blokovány. diff --git a/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..c7d557e58 --- /dev/null +++ b/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Požadováno | Popis | Example | +| :---------------- | :------------ | :--------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | celé číslo | Ne | Detected account ID, if any. | `1234` | +| `DnsServerId` | řetězec | Ne | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | řetězec | Ne | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | řetězec | Ne | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | řetězec | Ne | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | řetězec | Ano | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | řetězec | Ne | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | řetězec | Ne | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | celé číslo | Ano | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | celé číslo | Ne | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | celé číslo | Ano | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | celé číslo | Ano | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | celé číslo | Ano | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | celé číslo | Ano | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | celé číslo | Ano | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | celé číslo | Ano | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | celé číslo | Ano | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | řetězec | Ne | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Ano | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Ano | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## FAQ + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 0f799419c..37089fd7e 100644 --- a/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Protokol dotazů sidebar_position: 5 --- -## Co je protokol dotazů +## What is Query log? -Protokol dotazů je užitečný nástroj pro práci s AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. Umožňuje zobrazit všechny požadavky provedené vašimi zařízeními během zvoleného časového období a seřadit požadavky podle stavu, typu, společnosti, zařízení a země. ## Jak ho používat -Zde je uvedeno, co můžete vidět a co můžete udělat v _Protokolu dotazů_. +Here’s what you can see and what you can do in _Query log_. ### Podrobné informace o požadavcích -![Requests info \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Blokování a odblokování domén Požadavky lze blokovat a odblokovat bez opuštění protokolu pomocí dostupných nástrojů. -![Unblock domain \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Třídění požadavků diff --git a/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index 033827b5a..4578bc553 100644 --- a/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/cs/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS poskytuje širokou škálu užitečných nástrojů pro sledování - [Cíl datového provozu](/private-dns/statistics-and-log/traffic-destination.md) - [Společnosti](/private-dns/statistics-and-log/companies.md) - [Protokol dotazů](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/configuration.md b/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/configuration.md index 865a57eb2..692ea257e 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/configuration.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/configuration.md @@ -676,155 +676,155 @@ Indbygget DHCP-serveropsætning. Se også artiklen [DHCP][DHCPv4]. Den har flg. - `undernetmaske`: Undernetmaske. - - `range_start`, `range_end`: The start and the end of the leased IP address range. + - `range_start`, `range_end`: Starten og slutningen på området af lejede IP-adresser. - - `lease_duration`: Lease duration in seconds. If `0`, use the default duration of 24 hours. + - `lease_duration`: Lejemålsperiode i sekunder. Hvis `0`, anvend standardvarigheden på 24 timer. - - `icmp_timeout_msec`: Time to wait for an ICMP reply to detect an IP conflict, in milliseconds. If `0`, the feature is disabled. + - `icmp_timeout_msec`: Den tid (i millisekunder), der skal ventes på et ICMP-svar for at registrere en IP-konflikt. Hvis `0`, er funktionen deaktiveret. - - `options`: Custom DHCP options. See the [DHCP][DHCPv4] article section on these options for more information. + - `options`: Tilpassede DHCP-indstillinger. Se afsnittet om disse indstillinger i artiklen [DHCP][DHCPv4] for yderligere oplysninger. -- `dhcpv6`: DHCPv6 settings. It has the following properties: +- `dhcpv6`: DHCPv6-indstillinger. Den har flg. egenskaber: - - `range_start`: The first IP address to be assigned to a client. + - `range_start`: Den første IP-adresse, der skal tildeles en klient. - - `lease_duration`: Same as in v4 above. + - `lease_duration`: Samme som i v4 ovenfor. - - `ra_slaac_only` and `ra_allow_slaac`: Send RA packets either forcing the clients to use SLAAC or allowing them to choose. See the [DHCP][DHCPv6] article section on these options for more information. + - `ra_slaac_only` og `ra_allow_slaac`: Send RA-pakker, som enten tvinger klienterne til at anvende SLAAC eller muliggør egne valg. Se afsnittet om disse indstillinger i artiklen [DHCP][DHCPv6] for yderligere oplysninger. -- `local_domain_name`: The domain name that AdGuard Home’s DHCP server uses for hostnames of its clients. The default value, which is also set when this value is empty, is `lan`. So, if you have a machine called `myhost` in your network, and AdGuard Home is this network’s DHCP server, the hostname of that machine is `myhost.lan`. DNS-forespørgsler af typen `A` for sådanne værter er kun tilladt fra lokalt betjente netværk, såsom `10.0.0.0/8`, `192.168.0.0/16` mv. Other clients receive an empty `NXDOMAIN` response. +- `local_domain_name`: Domænenavnet AdGuard Homes DHCP-server anvender til værtsnavnene på sine klienter. Standardværdien, der også angives, når dette felt er tomt, er `lan`. Findes f.eks. en maskine med navnet `myhost` på netværket, hvor AdGuard Home er DHCP-serveren, vil maskinens værtsnavn være `myhost.lan`. DNS-forespørgsler af typen `A` for sådanne værter er kun tilladt fra lokalt betjente netværk, såsom `10.0.0.0/8`, `192.168.0.0/16` mv. Andre klienter modtager et tomt `NXDOMAIN`-svar. ### `tls` {#tls} -HTTPS/DoH/DoQ/DoT settings. It has the following properties: +Indstillinger for HTTPS/DoH/DoQ/DoT. Den har flg. egenskaber: -- `enabled`: Whether encryption (DoT/DoH+HTTPS/DoQ) is enabled. +- `enabled`: Hvorvidt kryptering (DoT/DoH+HTTPS/DoQ) er aktiveret. - **Example**: `true` + **Eksempel**: `true` -- `server_name`: The hostname of your server. If set, it is used to detect ClientIDs (using the _ServerName_ field of ClientHello messages), respond to [Discovery of Designated Resolvers (DDR)][DDR] queries, and perform additional connection validations. If not set, these features are disabled. It must match one of the DNS Names in the certificate. +- `server_name`: Værtsnavnet på den lokale server. Hvis angivet, benyttes den til at registrere ClientID'er (via feltet _ServerName_ i ClientHello-meddelelser), besvare [Discovery of Designated Resolvers (DDR)][DDR]-forespørgsler og udføre yderligere forbindelsesvalideringer. Hvis ikke angivet, er disse funktioner deaktiveret. Skal matche et af DNS-navnene i certifikatet. - **Example**: `example.org` + **Eksempel**: `example.org` -- `force_https`: If `true`, force HTTP-to-HTTPS redirect. This setting also sets the [`Strict-Transport-Security`][hsts] header. +- `force_https`: Hvis `true`, gennemtving HTTP-til-HTTPS omdirigering. Denne indstilling angiver også headeren [`Strict-Transport-Security`][hsts]. - **Example**: `true` + **Eksempel**: `true` -- `port_https`: The HTTPS port. Used for both web UI and DNS-over-HTTPS. If `0`, HTTPS is disabled. +- `port_https`: HTTPS-porten. Anvendes til både web-UI og DNS-over-HTTPS. Hvis `0`, er HTTPS deaktiveret. - **Example**: `443` + **Eksempel**: `443` -- `port_dns_over_tls`: The DNS-over-TLS port. If `0`, DNS-over-TLS is disabled. +- `port_dns_over_tls`: DNS-over-TLS-port. Hvis `0`, er DNS-over-TLS deaktiveret. - **Example**: `853` + **Eksempel**: `853` -- `port_dns_over_quic`: The DNS-over-QUIC port. If `0`, DNS-over-QUIC is disabled. Default value is `853`. +- `port_dns_over_quic`: DNS-over-QUIC-port. Hvis `0`, er DNS-over-QUIC deaktiveret. Standardværdien er `853`. -- `port_dnscrypt`: The DNSCrypt port. If `0`, DNSCrypt is disabled. See the “[DNSCrypt]” page for more information and examples. +- `port_dnscrypt`: DNSCrypt-port. Hvis `0`, er DNSCrypt deaktiveret. Se siden “[DNSCrypt]” for yderligere information og eksempler. -- `dnscrypt_config_file`: The path to the DNSCrypt configuration file. It must be set if `port_dnscrypt` is not `0`. See the [dnscrypt] utility documentation for examples of configuration generation. +- `dnscrypt_config_file`: Sti til DNSCrypt-opsætningsfilen. Den skal angives, såfremt `port_dnscrypt` ikke er `0`. Se dokumentationen til værktøjet [dnscrypt] for eksempler på opsætningsgenerering. -- `certificate_chain`: The PEM-encoded certificates chain. +- `certificate_chain`: PEM-kodede certifikatkæde. -- `strict_sni_check`: If `true`, reject connections if the client uses server name (in SNI) that doesn't match the one in the certificate. +- `strict_sni_check`: Hvis `true`, afvises forbindelser, hvis klienten bruger et servernavn (i SNI), der ikke matcher det i certifikatet. -- `private_key`: The PEM-encoded private key. +- `private_key`: PEM-kodet private nøgle. -- `certificate_path`: Filesystem path to a PEM certificate. +- `certificate_path`: Filsystemsti til et PEM-certifikat. -- `private_key_path`: Filesystem path to a PEM private key. +- `private_key_path`: Filsystemsti til en privat PEM-nøgle. -- `override_tls_ciphers`: If set, this array of strings allows overriding the default set of TLS cipher suites to use. The strings are the [names of cipher suites][tls-names]. +- `override_tls_ciphers`: Hvis angivet, muliggør denne strengmatrix at tilsidesætte standardsættet af TLS-krypteringspakker, som skal bruges. Strengene er [navnene på krypteringssuiter][tls-names]. ### `whitelist_filters` {#whitelist-filters} -List of **allow-list** filters. +Liste over **hvidliste**-filtre. ### `user_rules` {#user-rules} -User-specified filtering rules. +Brugerdefinerede filtreringsregler. ### `os` {#os} -Operating system related settings. +Indstillinger relateret til operativsystemet. -- `group`: The name of the user group to switch to after the startup. +- `group`: Navnet på den brugergruppe, der skal skiftes til efter opstart. -- `user`: The name of the user to switch to after the startup. +- `user`: Navnet på den bruger, der skal skiftes til efter opstart. -- `rlimit_nofile`: Limit on the maximum number of open files for the server process (on unixlike OSs). Set to `0` to use the system’s default value. +- `rlimit_nofile`: Begrænsning af det maksimale antal åbne filer for serverprocessen (på Unix-lignende operativsystemer). Indstil til `0` for brug af systemets standardværdi. ### `clients` {#clients} -Persistent and runtime clients settings. +Indstillinger for permanente og runtime-klienter. -- `persistent`: An array of explicitly configured clients. Each client has the following properties: +- `persistent`: En matrix af eksplicit opsatte klienter. Hver klient har flg. egenskaber: - `safe_search`: _Sikker søgning_-indstillingsafsnit. - - `blocked_services`: _Blocked services_ settings section. + - `blocked_services`: _Blokerede tjenester_-indstillingsafsnit. - - `name`: Client’s name. + - `navn`: Klientens navn. - - `ids`: List of client’s identifiers. + - `ids`: Liste over klientens identifikatorer. - - `tags`: List of client’s tags. + - `tags`: Liste over klientens tags. - - `upstreams`: Upstreams configuration. + - `upstreams`: Opsætning af upstreams. - - `uid`: Client’s unique identifier. + - `uid`: Klientens unikke identifikator. - - `upstreams_cache_size`: Client’s cache size. + - `upstreams_cache_size`: Klientens cachestørrelse. - - `upstreams_cache_enabled`: If client’s cache is enabled. + - `upstreams_cache_enabled`: Hvorvidt klientens cache er aktiveret. - - `use_global_settings`: Shows if the client-specific settings are used to override the global settings. + - `use_global_settings`: Viser, om de klientspecifikke indstillinger bruges til at tilsidesætte de globale indstillinger. - - `filtering_enabled`: Indicates whether or not to use filter lists. + - `filtering_enabled`: Angiver, hvorvidt filterlister skal benyttes eller ej. - - `parental_enabled`: Indicates whether or not to use parental protection. + - `parental_enabled`: Angiver, hvorvidt forældrebeskyttelse skal benyttes eller ej. - - `safebrowsing_enabled`: Indicates whether or not to use safe browsing protection. + - `safebrowsing_enabled`: Angiver, hvorvidt sikker browsing skal bruges eller ej. - - `use_global_blocked_services`: Shows if the client-specific settings are used to override the global Blocked Services settings. + - `use_global_blocked_services`: Viser, om de klientspecifikke indstillinger anvendes til at tilsidesætte de globale indstillinger for Blokerede tjenester. - - `ignore_querylog`: Indicates whether or not to exclude client’s activity from the query log. + - `ignore_querylog`: Angiver, hvorvidt klientens aktivitet skal undtages fra forespørgselsloggen. - - `ignore_statistics`: Indicates whether or not to exclude client’s activity from the statistics. + - `ignore_statistics`: Angiver, hvorvidt klientens aktivitet skal undtages fra statistikken eller ej. -- `runtime_sources`: This controls runtime-client data sources. +- `runtime_sources`: Dette styrer runtime-klientens datakilder. - - `whois`: Request WHOIS information for clients with public IP addresses. + - `whois`: Anmod om WHOIS-oplysninger for klienter med offentlige IP-adresser. - - `arp`: Consider the operating system’s ARP table. + - `arp`: Tager hensyn til operativsystemets ARP-tabel. - - `rdns`: Perform rDNS lookups for client’s address. + - `rdns`: Udfør rDNS-opslag for klientens adresse. - - `dhcp`: Check AdGuard Home’s DHCP leases for client’s address. + - `dhcp`: Tjek AdGuard Homes DHCP-lejemål for klientens adresse. - - `hosts`: Follow the operating system’s hosts files. + - `hosts`: Følg operativsystemets hosts-filer. ### `log` {#log} -Log settings. +Logindstillinger. -- `enabled`: Enable or disable writing to logs. +- `enabled`: Aktivér eller deaktivér skrivning til logfiler. -- `file`: Path to the log file. If empty, writes to stdout, if `syslog` writes system log (or eventlog on Windows). +- `file`: Sti til logfilen. Hvis tomt, skrives til stdout, såfremt `syslog` skriver systemloggen (eller hændelseslog i Windows). -- `compress`: If `true`, enabled GZIP compression of the log files. +- `compress`: Hvis `true`, aktiveres GZIP-komprimering af logfilerne. -- `local_time`: If `true`, the time used for formatting the timestamps is the computer’s local time. +- `local_time`: Hvis `true`, er tidspunktet brugt til formatering af tidsstemplerne computerens lokale tid. -- `max_backups`: Maximum number of old log files to retain. `0` means retain all old log files. Note that `max_age` may still cause them to be deleted. +- `max_backups`: Maksimalt antal gamle logfiler, som skal bevares. `0` betyder, at alle gamle logfiler bevares. Bemærk, at `max_age` stadig kan medføre, at de slettes. -- `max_size`: Maximum size of the log file before it gets rotated, in megabytes. +- `max_size`: Logfilens maksimalstørrelse, i megabyte, før den roteres. -- `max_age`: Maximum number of days to retain old log files. +- `max_age`: Maksimalt antal dage gamle logfiler skal beholdes. -- `verbose`: If `true`, enables verbose debug output. +- `verbose`: Hvis `true`, aktiveres detaljeret fejlfindingsoutput. -Removing an entry from settings file will reset it to the default value. Deleting the file will reset all settings to the default values. +Fjernes en post fra indstillingsfilen, nulstilles den til standardværdien. Slettes filen, nulstilles alle indstillinger til standardværdierne. [DDR]: https://www.ietf.org/archive/id/draft-ietf-add-ddr-06.html [DHCPv4]: /adguard-home/dhcp#dhcpv4-options @@ -834,11 +834,11 @@ Removing an entry from settings file will reset it to the default value. Deletin [rfc6147]: https://datatracker.ietf.org/doc/html/rfc6147 [tls-names]: https://pkg.go.dev/crypto/tls#pkg-constants -## Reset web password {#password-reset} +## Nulstil webadgangskode {#password-reset} -Please follow these steps to create a new password for your user account: +Følg disse trin for at oprette en ny brugerkontoadgangskode: -1. Install `htpasswd`, which is a part of _Apache2 Web Server:_ +1. Installér `htpasswd`, der er en del af _Apache2-webserveren:_ - Ubuntu: @@ -854,11 +854,11 @@ Please follow these steps to create a new password for your user account: - Windows: - Choose the appropriate [download][htpasswd], extract the downloaded folder, open a terminal, navigate to its `bin` directory with the `chdir` command, and run `.\Htpasswd`. Note the capital “H” in the Windows version. + Vælg den relevante [download][htpasswd], udpak den downloadede mappe, åbn en terminal, og gå til dens `bin`-mappe med kommandoen `chdir` og eksekvér dernæst `.\Htpasswd`. Bemærk majusklen “H” i Windows-versionen. - Other versions of `htpasswd` could be used, but **only** if they support _bcrypt_ hash encryption, which rules out e.g. most web-hosted `htpasswd` generators. + Andre versioner af `htpasswd` kan bruges, men **kun** såfremt de understøtter _bcrypt_-hashkryptering, hvilket udelukker f.eks. de fleste webbaserede `htpasswd`-generatorer. -2. Use the `htpasswd` utility to generate a new hash: +2. Brug værktøjet `htpasswd` til at generere en ny hash: - Ubuntu/Fedora: @@ -872,11 +872,11 @@ Please follow these steps to create a new password for your user account: .\Htpasswd -B -C 10 -n -b ``` - It will print `:` to the terminal. + Den vil printe `:` i terminalen. -3. Open `AdGuardHome.yaml` in a text editor with sudo rights. +3. Åbn `AdGuardHome.yaml` i en teksteditor med sudo-rettigheder. - In the `users:` section, find your username and insert the `` value for the `password` setting: + Find eget brugernavn i afsnittet `users:`, og indsæt værdien `` for indstillingen `password`: ```yaml users: @@ -884,25 +884,25 @@ Please follow these steps to create a new password for your user account: password: ``` -4. Save the file and restart AdGuard Home. Now you should be able to log in to the web interface using your new password. +4. Gem filen, og genstart AdGuard Home. Nu burde der kunne logges ind på webgrænsefladen med den nye adgangskode. [htpasswd]: https://httpd.apache.org/docs/current/platform/windows.html#down -## Profiling with pprof {#pprof} +## Profilering med pprof {#pprof} -To enable pprof, set `http.pprof.enabled` and `http.pprof.port` in the yaml configuration file and then restart AdGuard Home. Now you can get profiling information with your browser, for example `http://localhost:[PORT]/debug/pprof/goroutine?debug=2` will show the call trace of each running goroutine. +For at aktivere pprof skal `http.pprof.enabled` og `http.pprof.port` opsættes i YAML-opsætningsfilen og AdGuard Home dernæst genstartes. Nu kan profileringsoplysninger hentes via webbrowseren. F.eks. viser `http://localhost:[PORT]/debug/pprof/goroutine?debug=2` kaldsporet for hver kørende goroutine. -This URL lets you see information about the heap usage of the AdGuard Home process: `http://localhost:[PORT]/debug/pprof/heap?debug=1`. +Denne URL muliggør at se oplysninger om AdGuard Home-processens heap-forbrug: `http://localhost:[PORT]/debug/pprof/heap?debug=1`. -Or, with `go tool pprof`: +Eller med `go tool pprof`: ```sh go tool pprof -top http://localhost:6060/debug/pprof/heap ``` -For a list of supported profiles go to `http://localhost:6060/debug/pprof/`. +For at se en liste over understøttede profiler, gå til `http://localhost:6060/debug/pprof/`. -Alternatively, you may want to simply download the file and analyze it later: +Alternativt kan filen blot downloades og analyseres senere: ```sh wget http://localhost:6060/debug/pprof/heap diff --git a/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/dhcp.md b/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/dhcp.md index 256b5f454..157bfac1b 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/dhcp.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/dhcp.md @@ -3,48 +3,48 @@ title: DHCP sidebar_position: 10 --- -AdGuard Home can be used as a DHCP server. This page describes how to do that. +AdGuard Home kan anvendes som en DHCP-server. Denne side beskriver, hvorledes dette gøres. -## Prerequisites {#prerequisites} +## Forudsætninger {#prerequisites} -1. Make sure that you run an OS on which AdGuard Home supports DHCP. We currently don’t support DHCP on Windows. +1. Sørg for, at der anvendes et OS, under hvilket AdGuard Home understøtter DHCP. Vi understøtter p.t. ikke DHCP på Windows. -2. Make sure that your machine has a static IP address. +2. Sørg for, at maskinen er opsat med en statisk IP-adresse. -## Configuration {#configuration} +## Opsætning {#configuration} -See the [overview of the DHCP configuration options][dhcp-conf]. There are several parameters for DHCP that can’t be set via the AdGuard Home administrator dashboard. Those are described below. +Se [oversigten over DHCP-opsætningsindstillingerne][dhcp-conf]. Der er flere DHCP-parametre, som ikke kan opsættes via AdGuard Home-administratorpanelet. Disse beskrives nedenfor. :::note -By default, AdGuard Home will set itself as the DNS server for the DHCP clients. The default lease time is 24 hours. +AdGuard Home opsætter som standard sig selv som DNS-server for DHCP-klienterne. Standardlejeperioden er 24 timer. ::: [dhcp-conf]: /adguard-home/configuration#dhcp -### DHCPv4 options {#dhcpv4-options} +### DHCPv4-indstillinger {#dhcpv4-options} -The `options` field is used to explicitly specify the values for DHCP options and modify the response. In accordance with _Section 4.3.1_ of [RFC 2131][rfc-2131], these options override the default options’ values set by Adguard Home and requested by a client, which means that if you want to set custom DNS server addresses using option `6` (Domain Name Server), you may want also add Adguard Home’s own addresses there. Otherwise, AdGuard Home’s filtering won’t work for the DHCP clients who receive these DNS server addresses. +Feltet `options` bruges til eksplicit at angive værdierne for DHCP-indstillinger og ændre svaret. I overensstemmelse med _Afsnit 4.3.1_ i [RFC 2131][rfc-2131] tilsidesætter disse indstillinger standardindstillingernes værdier, som er indstillet af Adguard Home og anmodet om af en klient, hvilket betyder, at såfremt en tilpasset DNS-serveradresser ønskes opsat via indstilling `6` (Domænenavnserver), bør Adguard Homes egne adresser også tilføjes dér. Ellers virker AdGuard Homes filtrering ikke for de DHCP-klienter, som modtager disse DNS-serveradresser. -Any option begins with a code written as a decimal integer. See [RFC 2132][rfc-2132] for the actual DHCP option codes and allowed lengths. The code is followed by the option’s type and value. Currently the following types are supported: +Hver valgmulighed begynder med en kode skrevet som et decimalt heltal. Se [RFC 2132][rfc-2132] for de faktiske DHCP-indstillingskoder og tilladte længder. Koden efterfølges af indstillingens type og værdi. P.t. understøttes flg. typer: -- `bool`: Human-readable form of a boolean value, and has the length of 1 octet. +- `bool`: Læsevenlig form af en boolesk værdi og har en længde på 1 oktet. - **Example**: + **Eksempel**: ```yaml 'options': - - '19 bool 0' # Disable IP forwarding for hosts. - - '20 bool t' # Enable non-local source routing for hosts. - - '29 bool F' # Disable subnet mask discovery. - - '30 bool true' # Enable mask supplying for supporting hosts. - - '36 bool False' # Make the hosts use RFC 894 for ethernet encapsulation. + - '19 bool 0' # Deaktivér IP-videresendelse for værter. + - '20 bool t' # Aktivér ikke-lokal kilderutning for værter. + - '29 bool F' # Deaktivér registrering af undernetmaske. + - '30 bool true' # Aktivér levering af maske for understøttende værter. + - '36 bool False' # Få værterne til at bruge RFC 894 til Ethernet-indkapsling. ``` -- `del`: No-value option is used to unconditionally remove options from the server’s responses (which may lead to weird behaviors, use with caution). +- `del`: Indstillingen uden værdi bruges til ubetinget at fjerne indstillinger fra serverens svar (hvilket kan føre til mærkelig adfærd, så anvend med forsigtighed). - Since the list of options is interpreted sequentially from first to last, the subsequent option may override the previous ones. So this: + Da listen over indstillinger fortolkes sekventielt fra den første til den sidste, kan den efterfølgende indstilling tilsidesætte de foregående. Så dette: ```yaml 'options': @@ -54,45 +54,45 @@ Any option begins with a code written as a decimal integer. See [RFC 2132][rfc-2 - '20 bool F' ``` - instructs to remove the option `19`, and to set the option `20` to `false`. + angiver, at indstillingen `19` skal fjernes, og at indstillingen `20` skal sættes til `false`. -- `dur`: A human-readable form of a duration in the range of 0 to 4,294,967,296 seconds (approximately 136 days), consisting of _4_ octets, just like a 32-bit unsigned integer. +- `dur`: En læsevenlig repræsentation af en varighed i intervallet fra 0 til 4.294.967.296 sekunder (ca. 136 dage) bestående af _4_ oktetter, ligesom et 32-bit heltal uden fortegn. - **Example**: + **Eksempel**: ```yaml 'options': - '24 dur 10m' ``` -- `hex`: A sequence of hexadecimal numbers of arbitrary length. +- `hex`: En sekvens af hexadecimale tal af vilkårlig længde. - **Example**: + **Eksempel**: ```yaml 'options': - '25 hex 0044012801FC03EE05D407D211001FE645FA' ``` -- `ip`: Accepts an IPv4 address and has a length of _4_ octets, just like an IPv4 itself. +- `ip`: Accepterer en IPv4-adresse og har en længde på _4_ oktetter, ligesom selve IPv4-adressen. - **Example**: + **Eksempel**: ```yaml 'options': - '28 ip 192.168.0.255' ``` -- `ips`: Accepts a comma-separated list of IPv4 addresses. It has an arbitrary length, but is always a multiple of _4_ octets. +- `ips`: Accepterer en kommasepareret liste over IPv4-adresser. Den har en vilkårlig længde, men er altid et multiplum af _4_ oktetter. - **Example**: + **Eksempel**: ```yaml 'options': - '6 ips 1.2.3.4,1.2.3.5' ``` -- `text`: Accepts an arbitrary UTF-8 encoded string and has a length of encoded text. +- `text`: Accepterer en vilkårlig UTF-8-kodet streng og har længden af den kodede tekst. **Eksempel:** @@ -101,7 +101,7 @@ Any option begins with a code written as a decimal integer. See [RFC 2132][rfc-2 - '252 text http://server.domain/proxyconfig.pac' ``` -- `u8`: A decimal number in the range of 0 to 255 that takes _1_ octet, just like an unsigned 8-bit integer. +- `u8`: Et decimaltal i intervallet 0 til 255, der fylder _1_ oktet, ligesom et 8-bit heltal uden fortegn. **Eksempel:** @@ -110,7 +110,7 @@ Any option begins with a code written as a decimal integer. See [RFC 2132][rfc-2 - '23 u8 64' ``` -- `u16`: A decimal number in the range of 0 to 65535 that takes _2_ octets, just like an unsigned 16-bit integer. +- `u16`: Et decimaltal i intervallet 0 til 65535, der fylder _2_ oktetter, ligesom et 16-bit heltal uden fortegn. **Eksempel:** @@ -121,54 +121,54 @@ Any option begins with a code written as a decimal integer. See [RFC 2132][rfc-2 :::note -Thoroughly check that the option format and value are valid for the chosen type in accordance with [RFC 2132][rfc-2132] or others. AdGuard Home does not perform any option-specific validations. +Kontrollér grundigt, at indstillingens format og værdi er gyldige for den valgte type i overensstemmelse med [RFC 2132][rfc-2132] eller andre. AdGuard Home udfører ingen indstillingsspecifikke valideringer. ::: -Currently there is a set of options listed in _Appendix A_ of [RFC 2131][rfc-2131] with the default values chosen according to the documents mentioned there: - -| Option | Value | -| -------------------------------- | --------------------------------------------------------------- | -| IP Forwarding | Disabled | -| Non-Local Source Routing | Disabled | -| Maximum Datagram Reassembly Size | 576 bytes | -| Default IP Time-to-live | 64 seconds | -| Path MTU Aging Timeout Option | 10 minutes | -| Path MTU Plateau Table | See [Table 7.1 in RFC 1191][rfc-1191-tbl-7.1] | -| Interface MTU | 576 bytes | -| All subnets are local | False | -| Perform Mask Discovery | False | -| Mask Supplier | False | -| Perform Router Discovery | True | -| Router Solicitation Address | 224.0.0.2 | -| Broadcast Address | 255.255.255.255 | -| Use Trailer Encapsulation | False | -| ARP Cache Timeout | 1 minute | -| Ethernet Encapsulation version | RFC 894 | -| Default TCP TTL | 60 seconds | -| TCP Keepalive Interval | 2 hours | -| Put TCP Keepalive Garbage | True | -| Routere | `gateway_ip` from configuration | -| Subnet Mask | `subnet_mask` from configuration | - -Some of these values may appear obsolete or cause issues with certain DHCP client implementations. According to [RFC 2131][rfc-2131], the options are only returned if requested by the client within option `55` (Parameter Request List) when not explicitly configured. - -### DHCPv6 options {#dhcpv6-options} - -The option `dhcp.dhcpv6.ra_slaac_only`, if `true`, sends RA packets forcing the clients to use SLAAC. The DHCPv6 server won’t be started in this case. - -The option `dhcp.dhcpv6.ra_allow_slaac`, if `true`, sends RA packets allowing the clients to choose between SLAAC and DHCPv6. +Der er p.t. et sæt indstillinger angivet i _Bilag A_ i [RFC 2131][rfc-2131] med standardværdierne valgt iht. de dokumenter, som er nævnt der: + +| Indstilling | Værdi | +| ---------------------------------------- | --------------------------------------------------------------- | +| IP-videresendelse | Deaktiveret | +| Ikke-lokal kilderutning | Deaktiveret | +| Maksimal størrelse på datagramgensamling | 576 byte | +| Standard-IP-levetid | 64 sekunder | +| Indstilling for sti-MTU-aldringstimeout | 10 minutter | +| Stil-MTU-plateautabel | Se [Table 7.1 in RFC 1191][rfc-1191-tbl-7.1] | +| MTU-grænseflade | 576 byte | +| Alle undernet er lokale | Falsk | +| Udfør maskeopdagelse | Falsk | +| Maskeleverandør | Falsk | +| Udfør routeropdagelse | Sand | +| Router-anmodningsadresse | 224.0.0.2 | +| Broadcastadresse | 255.255.255.255 | +| Anvend trailerindkapsling | Falsk | +| ARP-cachetimeout | 1 minut | +| Ethernet-indkapslingsversion | RFC 894 | +| Standard TCP-TTL | 60 sekunder | +| TCP-keepalive-interval | 2 timer | +| Indsæt TCP Keepalive-skrammel | Sand | +| Routere | `gateway_ip` fra opsætning | +| Undernetmaske | `subnet_mask` fra opsætning | + +Nogle af disse værdier kan virke forældede eller forårsage problemer med visse DHCP-klientimplementeringer. Ifølge [RFC 2131][rfc-2131] returneres indstillingerne kun, hvis klienten anmoder om dem i indstilling `55` (Parameter Request List), når de ikke er opsat eksplicit. + +### DHCPv6-indstillinger {#dhcpv6-options} + +Er indstillingen `dhcp.dhcpv6.ra_slaac_only` angivet til `true`, sender den RA-pakker, som tvinger klienterne til at bruge SLAAC. DHCPv6-serveren startes ikke i dette tilfælde. + +Er indstillingen `dhcp.dhcpv6.ra_allow_slaac` angivet til `true`, sender den RA-pakker, som tillader klienterne at vælge mellem SLAAC og DHCPv6. [rfc-1191-tbl-7.1]: https://datatracker.ietf.org/doc/html/rfc1191#section-7.1 [rfc-2131]: https://datatracker.ietf.org/doc/html/rfc2131 [rfc-2132]: https://datatracker.ietf.org/doc/html/rfc2132 -## Automatic hosts {#auto-hosts} +## Automatiske værter {#auto-hosts} -Machines in the network can be reached more easily using the hostnames they send in the DHCP requests with a configurable top-level domain (TLD). By default, the TLD is `lan`. For example, if you have a machine called “workstation” in the network, and it sends a DHCP request with option 12 set to `workstation`, you can reach it over HTTP on the host `http://workstation.lan`. +Maskiner på netværket kan nemmere tilgås vha. de værtsnavne, de sender i DHCP-anmodningerne, med et opsætbart topdomæne (TLD). Som standard er TLD'et `lan`. Findes f.eks. en maskine med navnet “workstation” på netværket, og den sender en DHCP-anmodning med indstilling 12 angivet som `workstation`, kan den tilgås via HTTP på værten `http://workstation.lan`. -You can also set a custom TLD or domain name using the `dns.local_domain_name` field in the [configuration][dhcp-conf] file. +Der kan også angives et tilpasset TLDA eller domænenavn via feltet `dns.local_domain_name` i [opsætningsfilen][dhcp-conf]. -## Stored leases {#stored-leases} +## Gemte lejemål {#stored-leases} -DHCP leases are stored in `data/leases.json`. The file format is not stable and may change in the future releases. +DHCP-lejemål gemmes i `data/leases.json`. Filformatet er ikke stabilt og kan ændres i fremtidige udgivelser. diff --git a/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/docker.md b/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/docker.md index 738f88056..a951a6bb9 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/docker.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/docker.md @@ -3,29 +3,29 @@ title: Docker sidebar_position: 11 --- -This page provides specific guidelines for running AdGuard Home inside the Docker container. +Denne side indeholder specifikke retningslinjer for kørsel af AdGuard Home i Docker-containeren. -## Quick start {#quick-start} +## Hurtig start {#quick-start} -### Pull the Docker image +### Hent Docker-afbildning -This command will pull the latest stable version: +Denne kommando henter den seneste stabile version: ```sh docker pull adguard/adguardhome ``` -### Create directories for persistent configuration and data +### Opret mapper til permanent opsætning og data -The image exposes two volumes for data and configuration persistence. So, the following directories must be created on a suitable volume on the host system: +Afbildningen eksponerer to diskenheder til permanent lagring af data og opsætning. Flg. mapper skal derfor oprettes på en egnet diskenhed på værtssystemet: -- Data directory, for example `/my/own/workdir`. +- Datamappe, f.eks. `/min/egen/arbejdsmappe`. -- Configuration directory, for example `/my/own/confdir`. +- Opsætningsmappe, f.eks. `/min/egen/opsmappe`. -### Create and run the container +### Opret og kør containeren -Use the following command to create a new container and run AdGuard Home: +Brug flg. kommando til at oprette en ny container og køre AdGuard Home: ```sh docker run \ @@ -46,31 +46,31 @@ docker run \ ; ``` -The AdGuard Home service admin panel can now be accessed via http://127.0.0.1:3000/ from a web browser. +AdGuard Home-tjenestens admin-panel kan nu tilgås via http://127.0.0.1:3000/ fra en webbrowser. -The following port mappings might be needed: +Flg. porttildelinger kan være nødvendige: -- `-p 53:53/tcp -p 53:53/udp`: Required for plain DNS. +- `-p 53:53/tcp -p 53:53/udp`: Krævet til almindelig DNS. -- `-p 67:67/udp -p 68:68/tcp -p 68:68/udp`: Required for running a DHCP server. +- `-p 67:67/udp -p 68:68/tcp -p 68:68/udp`: Krævet for at køre en DHCP-server. -- `-p 80:80/tcp -p 443:443/tcp -p 443:443/udp -p 3000:3000/tcp`: Required for the admin panel and for running a [HTTPS/DNS-over-HTTPS][enc] server. +- `-p 80:80/tcp -p 443:443/tcp -p 443:443/udp -p 3000:3000/tcp`: Krævet til admin-panelet samt for at køre en [HTTPS/DNS-over-HTTPS][enc]-server. -- `-p 853:853/tcp`: Required for running a [DNS-over-TLS][enc] server. +- `-p 853:853/tcp`: Krævet for at køre en [DNS-over-TLS][enc]-server. -- `-p 853:853/udp`: Required for running a [DNS-over-QUIC][enc] server. +- `-p 853:853/udp`: Krævet for at køre en [DNS-over-QUIC][enc]-server. -- `-p 5443:5443/tcp -p 5443:5443/udp`: Required for running a [DNSCrypt] server. +- `-p 5443:5443/tcp -p 5443:5443/udp`: Krævet for at køre en [DNSCrypt]-server. -- `-p 6060:6060/tcp`: Required for running a pprof debug API. +- `-p 6060:6060/tcp`: Krævet for at køre en pprof debug-API. -### Client IPs +### Klient-IP'er -To make AdGuard Home see the original client IPs as opposed to something like `172.17.0.1`, the `--network host` argument must be added to the list of options. +For at få AdGuard Home til at se de oprindelige klient-IP'er i stedet for noget såsom `172.17.0.1` skal argumentet `--network host` føjes til listen over indstillinger. -### Control the container +### Styring af containeren -AdGuard Home container can be controlled using the following commands: +AdGuard Home-containeren kan styres med flg. kommandoer: - Start: @@ -84,7 +84,7 @@ AdGuard Home container can be controlled using the following commands: docker stop adguardhome ``` -- Remove: +- Fjern: ```sh docker rm adguardhome @@ -93,65 +93,65 @@ AdGuard Home container can be controlled using the following commands: [DNSCrypt]: /adguard-home/encryption#configure-dnscrypt [enc]: /adguard-home/encryption -## Update to a newer version {#update} +## Opdatering til en nyere version {#update} -1. Pull the new version from Docker Hub: +1. Hent den nye version fra Docker Hub: ```sh docker pull adguard/adguardhome ``` -2. Stop and remove currently running container (assuming the container is named `adguardhome`): +2. Stop og fjern den aktuelt kørende container (forudsat containeren hedder `adguardhome`): ```sh docker stop adguardhome docker rm adguardhome ``` -3. Create and start the container using the new image using the command from the previous section. +3. Opret og start containeren med de nye afbildning via kommandoen fra det foregående afsnit. -## Running development builds {#unstable} +## Kørsel af udviklings-builds {#unstable} -Unstable development builds might be accessed using `edge` or `beta` tags. In order to use it, simply replace `adguard/adguardhome` with `adguard/adguardhome:edge` or `adguard/adguardhome:beta` in every command from the quick start. F.eks.: +Ustabile udviklings-builds kan muligvis tilgås via tagsene `edge` eller `beta`. For at bruge det, erstat blot `adguard/adguardhome` med `adguard/adguardhome:edge` eller `adguard/adguardhome:beta` i hver kommando fra hurtigstartvejledningen. F.eks.: ```sh docker pull adguard/adguardhome:edge ``` -## Additional configuration {#configuration} +## Yderligere opsætning {#configuration} -Upon the first run, a file with the default values named `AdGuardHome.yaml` is created. This file can be modified while the AdGuard Home container is not running. Ellers vil evt. ændringer i filen gå tabt, da det kørende program vil overskrive dem. +Ved første kørsel oprettes en fil med standardværdierne ved navn `AdGuardHome.yaml`. Denne fil kan redigeres, når AdGuard Home-containeren ikke kører. Ellers vil evt. ændringer i filen gå tabt, da det kørende program vil overskrive dem. -The settings are stored in the [YAML] format. The documentation describing all configurable parameters and their values is available on [this page][conf]. +Indstillingerne gemmes i [YAML]-formatet. Dokumentationen, der beskriver alle opsætbare parametre og deres værdier, er tilgængelig på [denne side][conf]. [YAML]: https://yaml.org [conf]: /adguard-home/configuration -### Health-check +### Sundhedstjek -The recommended way to implement a health check mechanism is to create a new image tailored for the target configuration. Implementations may use the special domain name `healthcheck.adguardhome.test`, expecting it to return a `NODATA` response. Specifying this particular name within the `blocked_hosts` array under the `dns` section of the configuration file will break the health check because it imposes restrictions on usage of this name. The `allowed_clients` and `disallowed_clients` properties should also allow the client IP health check. +Den anbefalede måde at implementere en mekanisme til sundhedstjek på er at oprette en ny afbildning skræddersyet til målopsætningen. Implementeringer kan bruge det særlige domænenavn `healthcheck.adguardhome.test` i forventning om, at det returnerer et `NODATA`-svar. Angives dette specifikke navn i `blocked_hosts`-listen under afsnittet `dns` i opsætningsfilen, afbryder det sundhedstjekket, da det pålægger begrænsninger på brugen af dette navn. Egenskaberne `allowed_clients` og `disallowed_clients` bør også tillade klient-IP-sundhedstjekket. -## DHCP server {#dhcp} +## DHCP-server {#dhcp} -To use AdGuard Home’s DHCP server, the `--network host` argument should be passed when creating the container: +For at bruge AdGuard Home DHCP-serveren skal argumentet `--network host` videregives, når containeren oprettes: ```sh docker run --name adguardhome --network host ... ``` -This option instructs Docker to use the host’s network rather than a docker-bridged network. Note that port mapping with `-p` is not necessary in this case. +Denne indstilling angiver, at Docker skal bruge værtens netværk i stedet for et Docker-bridged netværk. Bemærk, at porttildeling med `-p` er unødvendig i dette tilfælde. :::note -The host networking driver only works on Linux hosts, and is not supported on Docker Desktop for Mac, Docker Desktop for Windows, or Docker EE for Windows Server. +Værtsnetværksdriveren fungerer kun på Linux-værter og understøttes ikke på Docker Desktop til Mac, Docker Desktop til Windows eller Docker EE til Windows Server. ::: -## `resolved` daemon {#resolved} +## `resolved`-dæmon {#resolved} -To run AdGuard Home on a system where the `resolved` daemon is started, `DNSStubListener` must be disabled to prevent port bind conflict: +For at køre AdGuard Home på et system, hvor `resolved`-dæmonen er startet, skal `DNSStubListener` deaktiveres for at forhindre porttilknytningskonflikt: -1. Deactivate `DNSStubListener` and update the DNS server address. Create a new file, `/etc/systemd/resolved.conf.d/adguardhome.conf` (creating the `/etc/systemd/resolved.conf.d` directory if needed) and add the following content to it: +1. Deaktivér `DNSStubListener` og opdatér DNS-serveradressen. Opret en ny fil, `/etc/systemd/resolved.conf.d/adguardhome.conf` (opret om nødvendigt mappen `/etc/systemd/resolved.conf.d`), og føj flg. indhold til den: ```ini [Resolve] @@ -159,9 +159,9 @@ To run AdGuard Home on a system where the `resolved` daemon is started, `DNSStub DNSStubListener=no ``` - Specifying `127.0.0.1` as the DNS server address is necessary because otherwise the nameserver will be `127.0.0.53` which doesn’t work without `DNSStubListener`. + Angivelse af `127.0.0.1` som DNS-serveradressen er nødvendig, da navneserveren ellers vil være `127.0.0.53`, hvilket ikke vil fungerer uden `DNSStubListener`. -2. Activate a new `resolv.conf` file: +2. Aktivér en ny `resolv.conf`-fil: ```sh mv /etc/resolv.conf /etc/resolv.conf.backup diff --git a/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/faq.md b/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/faq.md index 560c4713c..965656f8b 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/faq.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/faq.md @@ -179,7 +179,7 @@ Disse parametre kan pt. ikke indstilles fra UI'en, hvorfor opsætningsfilen skal ## Hvordan opsættes AdGuard Home som standard DNS-server? {#defaultdns} -See the [_Configuring Devices_ section](/adguard-home/getting-started#configure-devices) on the _Getting Started_ page. +Se [afsnittet _Opsætning af enheder_](getting-started.md#configure-devices) på siden _Kom godt i gang_. ## Findes nogen kendte begrænsninger? {#limitations} @@ -312,7 +312,7 @@ Anvendes TLS på den reverse-proxyserveren, behøver man ikke bruge TLS på AdGu Man kan indstille parameteren `trusted_proxies` til sin HTTP-proxys IP-adresse(r) for at få AdGuard Home til at tage headerne indeholdende den reelle klient IP-adresse i betragtning. Se siderne [opsætning][conf] og [kryptering][encr] for yderligere information. -[encr]: /adguard-home/encryption#reverse-proxy +[encr]: <> [conf]: /adguard-home/configuration ## Hvordan rettes "tilladelse nægtet"-fejl på Fedora? {#fedora} @@ -396,7 +396,7 @@ Hvis knappen ikke vises, eller en automatisk opdatering mislykkedes, kan opdater cp -r ./AdGuardHome.yaml ./data ~/my-agh-backup/ ``` -5. Udpak AdGuard Home-arkivet til en midlertidig mappe. For example, if you downloaded the archive to your `/tmp/` directory: +5. Udpak AdGuard Home-arkivet til en midlertidig mappe. Downloades arkivet f.eks. til mappen `/tmp/`: ```sh tar -C /tmp/ -f /tmp/AdGuardHome_linux_amd64.tar.gz -x -v -z diff --git a/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/getting-started.md b/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/getting-started.md index 43df8d76a..ec281115d 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/getting-started.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/getting-started.md @@ -21,7 +21,7 @@ For at installere AdGuard Home som en tjeneste, udpak arkivet, gå til mappen 'A - Brugere af **macOS 10.15 Catalina** og senere bør placere AdGuard Home-arbejdsmappen i mappen `/Applications`. -- For **Raspberry Pi** users, there is a separate [guide][raspberry-pi-guide]. +- For brugere af **Raspberry Pi** findes en separat [guide][raspberry-pi-guide]. [raspberry-pi-guide]: /adguard-home/raspberry-pi diff --git a/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/raspberry-pi.md b/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/raspberry-pi.md index 46e24c228..37f001dbb 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/raspberry-pi.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/adguard-home/raspberry-pi.md @@ -3,34 +3,34 @@ title: Raspberry Pi sidebar_position: 12 --- -You can install AdGuard Home on your [Raspberry Pi][pi] and use it to filter ads and save traffic. Once it is installed, you can use your AdGuard Home on any machine connected to the same local network. +AdGuard Home kan installeres på [Raspberry Pi][pi] og bruges til at filtrere reklamer og spare datatrafik. Når installeret, kan AdGuard Home benyttes på enhver enhed forbundet til det samme lokale netværk. [pi]: https://www.raspberrypi.org -## Prepare your Pi {#prepare} +## Klargør Pi {#prepare} -You’ll need a Raspberry Pi with network access and [SSH enabled][ssh]. Connect it to a display and a keyboard, boot it, and write down the IP address that has been assigned to your Pi: +Der skal bruges en Raspberry Pi med netværksadgang samt [SSH aktiveret][ssh]. Slut den til en skærm og et tastatur, start den op og notér IP-adresse, som Pi-enheden er blevet tildelt: ```sh hostname -I | xargs -n 1 ``` -If there are several IP addresses, write down the first one. Switch back to your main computer, but keep your Pi running, and launch an ssh client. On Windows, you can use [PuTTY][putty], while on Linux, macOS, and other Unix-like OSes, you can just use your preferred terminal emulator. +Findes flere IP-adresser, notér den første. Skift til den primære computer, mens Pi-enheden fortsat kører, og start en SSH-klient. På Windows kan der bruges [PuTTY][putty], mens der på Linux, macOS og andre Unix-lignende OS'er blot kan bruge den foretrukne terminalemulator. -Type: +Skriv: ```sh ssh pi@192.168.10.20 ``` -(where `192.168.10.20` is the IP you’ve written down) and then type your Pi’s password (which is `raspberry` unless you’ve changed it already). Once you’re done, you will be greeted by the command-line interface. Now you’re ready to install your own AdGuard Home! +(hvor `192.168.10.20` er den IP-adresse, der blev noteret), og skriv dernæst adgangskoden til Pi-enheden (som er `raspberry`, hvis den ikke allerede er blevet skiftet). Når det er klaret, vises kommandolinjegrænsefladen. Nu er alt klar til installationen af AdGuard Home! [ssh]: https://www.raspberrypi.com/documentation/computers/remote-access.html [putty]: https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html -## Install AdGuard Home {#install} +## Installation af AdGuard Home {#install} -Go to the [AdGuard Home page][inst] and download the binaries for Raspberry Pi: +Gå til [AdGuard-websiden][inst] og download de binære filer til Raspberry Pi: ```sh cd @@ -38,36 +38,36 @@ wget 'https://static.adguard.com/adguardhome/release/AdGuardHome_linux_armv6.tar tar -f AdGuardHome_linux_armv6.tar.gz -x -v ``` -Replace `armv6` with the ARM version that is best supported by your Pi. +Erstat `armv6` med den ARM-version, der understøttes bedst af Pi-enheden. -That command unpacks the necessary data into a new directory called `AdGuardHome`. +Denne kommando udpakker de nødvendige data til et ny mappe ved navn `AdGuardHome`. -Then, install AdGuard Home as a [service]. +Installér dernæst AdGuard Home som en \[tjeneste]. [service]: /adguard-home/getting-started#service [inst]: https://github.com/AdguardTeam/AdGuardHome -## Check the filtering {#check} +## Tjek filtreringen {#check} -You can verify that it’s working properly by running this on your Pi: +Det kan tjekkes, om den fungerer korrekt, ved at køre denne på Pi-enheden: ```sh host doubleclick.net 127.0.0.1 ``` -If everything works correctly, you will get this output: +Fungerer alt korrekt, vises dette output: ```sh -Using domain server: -Name: 127.0.0.1 -Address: 127.0.0.1#53 -Aliases: +Bruger domæneserver: +Navn: 127.0.0.1 +Adresse: 127.0.0.1#53 +Aliasser: -Host doubleclick.net not found: 3(NXDOMAIN) +Værten doubleclick.net blev ikke fundet: 3(NXDOMAIN) ``` -## Configure your devices {#devices} +## Opsæt relevante enheder {#devices} -Once it is confirmed that AdGuard Home works on your Raspberry Pi, you can use it on other computers in your network by changing their system DNS settings to use the Pi’s IP address. +Når det er bekræftet, at AdGuard Home fungerer på Raspberry Pi-enheden, kan den benyttes på andre computere på netværket ved at ændre deres system-DNS-indstillinger, så de bruger Pi-enhedens IP-adresse. -Go to the _Setup Guide_ page in the web interface and follow the instructions. +Gå til siden _Opsætningsvejledning_ i webgrænsefladen og følg instruktionerne. diff --git a/i18n/da/docusaurus-plugin-content-docs/current/dns-client/configuration.md b/i18n/da/docusaurus-plugin-content-docs/current/dns-client/configuration.md index 80a025acc..4a7c0428d 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/dns-client/configuration.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/dns-client/configuration.md @@ -12,11 +12,11 @@ Se filen [`config.dist.yml`][dist] for et fuldstændigt eksempel på en [YAML][y ## `dns` {#dns} -`dns`-objektet opsætter adfærden for DNS-serveren. It has the following properties: +`dns`-objektet opsætter adfærden for DNS-serveren. Det har flg. egenskaber: ### `cache` {#dns-cache} -`cache`-objektet opsætter caching af DNS-forespørgselsresultaterne. It has the following properties: +`cache`-objektet opsætter caching af DNS-forespørgselsresultaterne. Det har flg. egenskaber: - 'enabled': Hvorvidt DNS-resultaterne skal cachelagres eller ej. @@ -32,9 +32,9 @@ Se filen [`config.dist.yml`][dist] for et fuldstændigt eksempel på en [YAML][y ### `server` {#dns-server} -`server`-objektet opsætter håndteringen af indgående forespørgsler. It has the following properties: +`server`-objektet opsætter håndteringen af indgående forespørgsler. Det har flg. egenskaber: -- `bind_retry`: The configuration of the retry mechanism for binding to the listen addresses. Dette er nyttigt, hvis serveren startes, før netværket er klar, og adresserne endnu ikke er tilgængelige, som på visse Windows-versioner når installeret som en systemtjeneste. +- `bind_retry`: Opsætningen af genforsøgsmekanismen for knytning til lytteadresserne. Dette er nyttigt, hvis serveren startes, før netværket er klar, og adresserne endnu ikke er tilgængelige, som på visse Windows-versioner når installeret som en systemtjeneste. :::note @@ -42,7 +42,7 @@ Se filen [`config.dist.yml`][dist] for et fuldstændigt eksempel på en [YAML][y ::: - It has the following properties: + Det har flg. egenskaber: - `enabled`: Om tilknytnings-genforsøg er aktiveret eller ej. @@ -80,7 +80,7 @@ Se filen [`config.dist.yml`][dist] for et fuldstændigt eksempel på en [YAML][y ### `bootstrap` {#dns-bootstrap} -`bootstrap`-objektet opsætter opløsningen af [upstream](#dns-upstream) serveradresser. It has the following properties: +`bootstrap`-objektet opsætter opløsningen af [upstream](#dns-upstream) serveradresser. Det har flg. egenskaber: - `servers`: Listen over servere til at opløse værtsnavnene på upstream-servere. @@ -98,9 +98,9 @@ Se filen [`config.dist.yml`][dist] for et fuldstændigt eksempel på en [YAML][y ### `upstream` {#dns-upstream} -'upstream'-objektet opsætter den faktiske forespørgselsopløsning. It has the following properties: +'upstream'-objektet opsætter den faktiske forespørgselsopløsning. Det har flg. egenskaber: -- `groups`: Sættet af upstream-servere med gruppens navn som nøgle. It has the following properties: +- `groups`: Sættet af upstream-servere med gruppens navn som nøgle. Det har flg. egenskaber: - `adresse`: Adressen på upstream-serveren. Er `autodevice.enabled` sat til `true` for denne gruppe, skal adressen være en URL med et af skemaerne `https`, `tls` eller `quic`. @@ -114,7 +114,7 @@ Se filen [`config.dist.yml`][dist] for et fuldstændigt eksempel på en [YAML][y ::: - It has the following properties: + Det har flg. egenskaber: - `enabled`: Definerer om alle klienter i den aktuelle gruppe kan forbindes automatisk. @@ -177,7 +177,7 @@ Se filen [`config.dist.yml`][dist] for et fuldstændigt eksempel på en [YAML][y ### `fallback` {#dns-fallback} -`fallback`-objektet opsætter adfærden for DNS-serveren i tilfælde af fejl. It has the following properties: +`fallback`-objektet opsætter adfærden for DNS-serveren i tilfælde af fejl. Det har flg. egenskaber: - `servers`: Listen over servere til brug ved manglende svar fra den aktuelle [upstream](#dns-upstream). @@ -198,11 +198,11 @@ Se filen [`config.dist.yml`][dist] for et fuldstændigt eksempel på en [YAML][y ## `debug` {#debug} -`debug`-objektet opsætter fejlfindingsfunktionerne. It has the following properties: +`debug`-objektet opsætter fejlfindingsfunktionerne. Det har flg. egenskaber: ### `pprof` {#debug-pprof} -`pprof`-objektet opsætter [`pprof`][pkg-pprof] HTTP-rutiner. It has the following properties: +`pprof`-objektet opsætter [`pprof`][pkg-pprof] HTTP-rutiner. Det har flg. egenskaber: - `port`: Porten, der skal lyttes til efter fejlfindings HTTP-forespørgsler på localhost. @@ -216,7 +216,7 @@ Se filen [`config.dist.yml`][dist] for et fuldstændigt eksempel på en [YAML][y ## `log` {#log} -"log"-objektet opsætter logningen. It has the following properties: +"log"-objektet opsætter logningen. Det har flg. egenskaber: - `output`: Det output, hvortil logger skrives. diff --git a/i18n/da/docusaurus-plugin-content-docs/current/general/dns-filtering-syntax.md b/i18n/da/docusaurus-plugin-content-docs/current/general/dns-filtering-syntax.md index daa118f9f..464270f93 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/general/dns-filtering-syntax.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/general/dns-filtering-syntax.md @@ -497,25 +497,25 @@ Oversigt over gyldige tags: :::note -The `respgeo` modifier can only be used in AdGuard DNS. +Modifikatoren `respgeo` kan kun bruges i AdGuard DNS. ::: -The `respgeo` modifier allows you to apply rules based on the country or ASN of the IP address returned in the DNS response. It checks the **destination** IP address — the IP address the domain resolves to. It does **not** check the IP address, country, or ASN of the user, device, or DNS client. +Modifikatoren `respgeo` muliggør anvendelse af regler baseret på landet eller ASN for den i DNS-svaret returnerede IP-adresse. Den tjekker **destinations**-IP-adressen — den IP-adresse, domænet opløses til. Den tjekker **ikke** IP-adressen, landet eller ASN for brugeren, enheden eller DNS-klienten. -##### Blocking by response country +##### Blokering efter svarland -The value of the modifier must be a two-letter country code in ISO 3166-1 alpha-2 format. You can also use `--` to match responses where the country could not be determined. +Værdien af modifikatoren skal være en tobogstavs landekode i ISO 3166-1 alpha-2-format. Der kan også bruges `--` til at matche svar, hvori landet ikke kunne bestemmes. **Eksempler:** -- `||*^$respgeo=US`: block domains if the IP address in the DNS response is associated with the United States. -- `||*^$respgeo=FR|DE`: block domains if the IP address in the DNS response is associated with France or Germany. -- `||*^$respgeo=--`: block domains if the country of the IP address in the DNS response is unknown. -- `||*^$respgeo=~--`: block domains if the country of the IP address in the DNS response is known. -- `@@||whitehouse.gov^`: allow `whitehouse.gov`, even if it is blocked by a wildcard rule with the `respgeo` modifier. -- `@@||example.org^$respgeo=US`: allow `example.org` if the IP address in the DNS response is associated with the United States. -- `||whitehouse.gov^$respgeo=US`: blocks `whitehouse.gov` only if the IP address in the DNS response is associated with the United States. +- `||*^$respgeo=US`: blokér domæner, hvis IP-adressen i DNS-svaret er tilknyttet USA. +- `||*^$respgeo=FR|DE`: blokér domæner, hvis IP-adressen i DNS-svaret er tilknyttet Frankrig eller Tyskland. +- `||*^$respgeo=--`: blokér domæner, hvis IP-adressens land i DNS-svaret er ukendt. +- `||*^$respgeo=~--`: blokér domæner, hvis IP-adressens land i DNS-svaret er kendt. +- `@@||whitehouse.gov^`: tillad `whitehouse.gov`, selv hvis det er blokeret af en jokertegnsregel med modifikatoren `respgeo`. +- `@@||example.org^$respgeo=US`: tillad `example.org`, hvis IP-adressen i DNS-svaret er tilknyttet USA. +- `||whitehouse.gov^$respgeo=US`: blokerer kun `whitehouse.gov`, hvis IP-adressen i DNS-svaret er tilknyttet USA. - I dette eksempel: ```none @@ -523,40 +523,40 @@ The value of the modifier must be a two-letter country code in ISO 3166-1 alpha- @@||whitehouse.gov^$respgeo=US ``` - `@@||whitehouse.gov^$respgeo=US` will **not** allow `whitehouse.gov`, because the first rule blocks the query by inspecting request data, while the second tries to allow it by inspecting the response. + `@@||whitehouse.gov^$respgeo=US` vil **ikke** tillade `whitehouse.gov`, da den første regel blokerer forespørgslen ved at inspicere forespørgselsdata, mens den anden forsøger at tillade den ved at inspicere svaret. -You can use `~` to invert the condition: +Der kan bruges `~` til at invertere betingelsen: -- `||*^$respgeo=~DE`: block domains if the IP address in the DNS response is **not** associated with Germany. +- `||*^$respgeo=~DE`: blokér domæner, hvis IP-adressen i DNS-svaret **ikke** er tilknyttet Tyskland. -**Limitations** +**Begrænsninger** -The `respgeo` modifier uses a single calculated IP address and country according to the current *Query log* logic. If a domain resolves to multiple IP addresses or countries, AdGuard DNS does not analyze all returned IP addresses. +Modifikatoren `respgeo` bruger en enkelt beregnet IP-adresse og land iht. den aktuelle logik for *Forespørgselslog*. Hvis et domæne opløses til flere IP-adresser eller lande, analyserer AdGuard DNS ikke alle returnerede IP-adresser. -Because many domains use CDNs, load balancing, or geographically distributed infrastructure, the detected country may change over time. +Da mange domæner bruger CDN'er, belastningsfordeling eller geografisk distribueret infrastruktur, kan det registrerede land ændre sig over tid. -If the country cannot be determined, the GeoIP condition will not match. Use `respgeo=--` to match responses with an unknown country. +Hvis landet ikke kan bestemmes, vil GeoIP-betingelsen ikke matche. Brug `respgeo=--` til at matche svar med et ukendt land. -Rules with the `respgeo` modifier are displayed in the *Query log* as regular rules. +Regler med modifikatoren `respgeo` vises i *Forespørgselslog* som almindelige regler. -##### Blocking by ASN +##### Blokering efter ASN -The `respgeo` modifier can also be used to apply rules based on the ASN of the IP address returned in the DNS response. +Modifikatoren `respgeo` kan også bruges til at anvende regler baseret på ASN for den IP-adresse, der returneres i DNS-svaret. -ASN stands for **Autonomous System Number**. It identifies an autonomous system — a network operated by an ISP, hosting provider, cloud provider, company, or other organization. +ASN står for **Autonomous System Number**. Det identificerer et autonomt system — et netværk drevet af en ISP, hostingudbyder, cloududbyder, virksomhed eller anden organisation. -This modifier checks the **destination ASN** — the ASN associated with the IP address the domain resolves to. It does **not** check the ASN of the user, device, or DNS client. +Denne modifikator tjekker **destinations-ASN** — det ASN, der er tilknyttet den IP-adresse, domænet opløses til. Den tjekker **ikke** brugerens, enhedens eller DNS-klientens ASN. -The value of the modifier must be an ASN in the `AS` format, for example `AS15169`. +Værdien af modifikatoren skal være et ASN i formatet `AS`, f.eks. `AS15169`. **Eksempler:** -- `||*^$respgeo=AS15169`: block domains if the IP address in the DNS response belongs to ASN AS15169. -- `||*^$respgeo=AS15169|AS8075`: block domains if the IP address in the DNS response belongs to ASN AS15169 or AS8075. -- `||*^$respgeo=AS--`: block domains if the ASN of the IP address in the DNS response is unknown. -- `||*^$respgeo=~AS--`: block domains if the ASN of the IP address in the DNS response is known. -- `@@||google.com^$respgeo=AS15169`: allow `google.com` if the IP address in the DNS response belongs to ASN AS15169. -- `||google.com^$respgeo=AS15169`: block `google.com` only if the IP address in the DNS response belongs to ASN AS15169. +- `||*^$respgeo=AS15169`: blokér domæner, hvis IP-adressen i DNS-svaret tilhører ASN AS15169. +- `||*^$respgeo=AS15169|AS8075`: blokér domæner, hvis IP-adressen i DNS-svaret tilhører ASN AS15169 eller AS8075. +- `||*^$respgeo=AS--`: blokér domæner, hvis IP-adressens ASN i DNS-svaret er ukendt. +- `||*^$respgeo=~AS--`: blokér domæner, hvis IP-adressens ASN i DNS-svaret er kendt. +- `@@||google.com^$respgeo=AS15169`: tillad `google.com`, hvis IP-adressen i DNS-svaret tilhører ASN AS15169. +- `||google.com^$respgeo=AS15169`: blokér kun `google.com`, hvis IP-adressen i DNS-svaret tilhører ASN AS15169. - I dette eksempel: ```none @@ -564,23 +564,23 @@ The value of the modifier must be an ASN in the `AS` format, for example @@||google.com^$respgeo=AS15169 ``` - `@@||google.com^$respgeo=AS15169` will **not** allow `google.com`, because the first rule blocks the query by inspecting request data, while the second tries to allow it by inspecting the response. + `@@||google.com^$respgeo=AS15169` vil **ikke** tillade `google.com`, da den første regel blokerer forespørgslen ved at inspicere forespørgselsdata, mens den anden forsøger at tillade den ved at inspicere svaret. -You can use `~` to invert the condition: +Der kan bruges `~` til at invertere betingelsen: -- `||*^$respgeo=~AS15169`: block domains if the IP address in the DNS response does **not** belong to ASN AS15169. +- `||*^$respgeo=~AS15169`: blokér domæner, hvis IP-adressen i DNS-svaret **ikke** tilhører ASN AS15169. -**Limitations** +**Begrænsninger** -The `respgeo` modifier uses a single calculated IP address and ASN according to the current *Query log* logic. If a domain resolves to multiple IP addresses or ASNs, AdGuard DNS does not analyze all returned ASNs. +Modifikatoren `respgeo` bruger en enkelt beregnet IP-adresse og ASN iht. den aktuelle logik for *Forespørgselslog*. Hvis et domæne opløses til flere IP-adresser eller ASN'er, analyserer AdGuard DNS ikke alle returnerede ASN'er. -Large CDN, cloud, or hosting ASNs may contain many unrelated websites. Blocking an ASN may therefore affect more domains than expected. +Store CDN-, cloud- eller hosting-ASN'er kan indeholde mange urelaterede websteder. Blokering af et ASN kan derfor påvirke flere domæner end forventet. -If the ASN cannot be determined, the ASN condition will not match. Use `respgeo=AS--` to match responses with an unknown ASN. +Kan ASN'et ikke bestemmes, vil ASN-betingelsen ikke matche. Benyt `respgeo=AS--` til at matche svar med et ukendt ASN. -ASN does not always correspond to a specific company, product, or service. It only identifies the network associated with the resolved IP address. +ASN korresponderer ikke altid med en bestemt virksomhed/produkt/tjeneste. Det identificerer kun det netværk, der er tilknyttet den opløste IP-adresse. -Rules with the `respgeo` modifier are displayed in the *Query log* as regular rules. +Regler med modifikatoren `respgeo` vises i *Forespørgselslog* som almindelige regler. ## `/etc/hosts`-syntakstype {#etc-hosts-syntax} diff --git a/i18n/da/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/da/docusaurus-plugin-content-docs/current/general/dns-providers.md index 11b000c79..aba9909a7 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor er en gratis, alternativ DNS-tjeneste fra Hur | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Føj til AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Føj til AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Føj til AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Føj til AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) leverer offentligt tilgængelig DNS med QNAME-minimering, endepunkter placeret i Singapore, Storbritannien, Sverige, Tyskland og USA (Dallas og New York). - -#### Ikke-filtrerende - -| Protokol | Adresse | | -| -------------- | ----------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Føj til AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Føj til AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Føj til AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Føj til AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Adblocking - -| Protokol | Adresse | | -| -------------- | ------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Føj til AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Føj til AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Føj til AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Føj til AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Annonce- + malware-blokering - -| Protokol | Adresse | | -| -------------- | ---------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Føj til AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Føj til AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Føj til AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Føj til AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Annonce- + malware- + sociale medier-blokering - -| Protokol | Adresse | | -| -------------- | -------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Føj til AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Føj til AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Føj til AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Føj til AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Annonce- + malware- + voksen- + hasardspilsblokering - -| Protokol | Adresse | | -| -------------- | ------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Føj til AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Føj til AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Føj til AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Føj til AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Annonce- + malware- + voksen- + hasardspils- + sociale medier-blokering - -| Protokol | Adresse | | -| -------------- | --------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Føj til AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Føj til AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Føj til AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Føj til AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) er et anycast internetfiltreringssystem, der beskytter børn mod upassende websteder og krænkende indhold. @@ -611,7 +565,7 @@ Alm. DNS-servere med beskyttelse mod phishing og spyware. De inkluderer sortlist #### Ikke-sikret -Ikke-sikrede DNS-servere tilbyder ingen sikkerhedssortliste, DNSSEC eller EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protokol | Adresse | | | -------------- | ---------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md index 6ef008279..d955ac002 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md @@ -9,7 +9,7 @@ Med DNS-over-HTTPS med godkendelse kan man at indstille et brugernavn og adgangs Dette bidrager til at forhindre uautoriserede brugere i at tilgå den og forbedrer sikkerheden. Derudover kan man begrænse brugen af andre protokoller for bestemte profiler. Denne funktion er især nyttig, når andre kender den DNS-serveradresse, man bruger. Ved at tilføje en adgangskode, kan man blokere adgangen og sikre, at man kun kan bruge den selv. -## Sådan opsættes det +## How to set it up :::note Kompatibilitet diff --git a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/cudy.md b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/cudy.md index ea4360885..e7a50aa0d 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/cudy.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/cudy.md @@ -5,102 +5,102 @@ sidebar_position: 12 :::info -- Ad Shield allows AdGuard DNS to provide network-level filtering of ads, trackers, and other unwanted content. Running at the router level, it protects all connected devices and improves privacy across browsing, streaming, and app usage. -- This feature is available for Cudy routers with firmware version 2.5.0+. -- TR3000 is shown as an example in this tutorial. +- Ad Shield muliggør, at AdGuard DNS kan filtrere annoncer, trackere og andet uønsket indhold på netværksniveau. Kørende på routerniveau, beskytter den alle tilsluttede enheder og forbedrer fortroligheden på tværs af surfing, streaming og app-brug. +- Denne funktion er tilgængelig på Cudy-routere med firmwareversion 2.5.0+. +- TR3000 bruges som et eksempel i denne vejledning. ::: -## Use the Cudy app +## Brug af Cudy-appen -1. Connect your phone to the router’s Wi-Fi network. +1. Tilslut mobilen til routerens Wi-Fi-netværk. -2. Download the Cudy app on your phone. +2. Download Curdy-appen på mobilen. -[Download for Android](https://play.google.com/store/apps/details?id=com.cudy.cloudapp) +[Download til Android](https://play.google.com/store/apps/details?id=com.cudy.cloudapp) -[Download for iOS](https://apps.apple.com/sg/app/cudy/id6464377818) +[Download til iOS](https://apps.apple.com/sg/app/cudy/id6464377818) -1. Open the Cudy App on your phone. Tick _I agree with the Privacy Policy and the Terms of Sale_ and select _Local Management_. +1. Åbn Cudy-appen på mobilen. Markér _Jeg accepterer Fortrolighedspolitik og Salgsbetingelser_, og vælg _Lokal håndtering_. ![App](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy1.png) -1. Select _Wi-Fi Device_. +1. Vælg _Wi-Fi-enhed_. -![Wi-Fi select](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy2.png) +![Wi-Fi-valg](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy2.png) :::tip -If you have managed other types of devices on the Cudy App before, you may need to tap the menu icon (☰) on the left of _Dashboard_ to switch to _Wi-Fi Device_. +Er der tidligere håndteret andre enhedstyper i Cudy-appen, skal der muligvis trykkes på menuikonet (☰) til venstre for _Kontrolpanel_ for at skifte til _Wi-Fi-enhed_. ::: -1. Tap the router. +1. Tryk på routeren. -![Router select](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy3.png) +![Routervalg](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy3.png) -1. Enter the router's administrator password. Create one if this is your login for the first time. +1. Angiv routerens administratoradgangskode. Opret én, hvis der logges ind for første gang. -![Router auth](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy4.png) +![Routergodkendelse](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy4.png) -1. Tap Ad Shield. +1. Tryk på Ad Shield. ![Ad Shield](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy5.png) -1. Toggle on to enable Ad Shield. +1. Slå til for at aktivere Ad Shield. -![Ad Shield enable](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy6.png) +![Ad Shield-aktivering](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy6.png) -1. Select a "AdGuard DNS". +1. Vælg en "AdGuard DNS". ![AdGuard DNS](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy7.png) :::note -AdGuard DNS requires Cudy App V1.5.5+ +AdGuard DNS kræver Cudy-app V1.5.5+ ::: -1. Tick _I agree to the AdGuard DNS privacy policy_, and click _Confirm_. +1. Markér _Jeg accepterer AdGuard DNS Fortrolighedspolitik_, og klik på _Bekræft_. -![Privacy policy](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy8.png) +![Fortrolighedspolitik](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy8.png) -1. Enter your AdGuard DNS account username and password, and click _Continue_. +1. Angiv brugernavn og adgangskode til AdGuard DNS-kontoen, og klik på _Fortsæt_. -![Authorization](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy9.png) +![Godkendelse](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy9.png) -1. Set a Device Name, keep DNS Server as _Default_, and tap the ✔ icon at the top right. +1. Angiv et Enhedsnavn, bibehold DNS-serveren som _Standard_ og tryk på ✔-ikonet øverst til højre. -![Device name](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy10.png) +![Enhedsnavn](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy10.png) -1. Now AdGuard DNS is working to help block ads or other unwanted contents. For more settings, click _Go to Dashboard_. +1. AdGuard DNS assisterer nu med at blokere annoncer eller andet uønsket indhold. For yderligere indstillinger, klik på _Gå til Kontrolpanel_. -![Go to Dashboard](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy11.png) +![Gå til Kontrolpanel](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy11.png) -## Using the Web Interface +## Brug af webgrænseflade -1. Log in your router's web interface at cudy.net or 192.168.10.1. +1. Log ind på routerens webgrænseflade via cudy.net eller 192.168.10.1. -2. Go to _Advanced Settings_ → _Security_ → _Ad Shield_. +2. Gå til _Avancerede indstillinger_ → _Sikkerhed_ → _Ad Shield_. -![Advanced settings](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy12.png) +![Avancerede inds5](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy12.png) -1. Enable _Ad Shield_ and select AdGuard DNS as the service provider. +1. Aktivér _Ad Shield_ og vælg AdGuard DNS som tjenesteudbyder. -2. Tick _I agree to the AdGuard DNS Privacy policy_ and click _Save & Apply_. +2. Markér _Jeg accepterer AdGuard DNS Fortrolighedspolitik_, og klik på _Gem og Anvend_. -![Privacy policy](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy13.png) +![Fortrolighedspolitik](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy13.png) -1. Log in your Adguard DNS account with the username and password, and click _Continue_. +1. Log ind på AdGuard DNS-kontoen med brugernavn og adgangskode, og klik på _Fortsæt_. -![Username and password](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy14.png) +![Brugernavn og adgangskode](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy14.png) -1. Set _Device Name_, select _Default_ in _DNS Server_, and click _Save & Apply_. +1. Angiv _Enhedsnavn_, vælg _Standard_ under _DNS-server_, og klik på _Gem og Anvend_. -![Device name](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy15.png) +![Enhedsnavn](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy15.png) 1. Check the _Active_ status on _System Status_ → _Ad Shield_ and click _Go to Dashboard_ to set up AdGuard DNS. -![Active](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy16.png) +![Aktiv](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy16.png) -![Dashboard](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy17.png) +![Kontrolpanel](https://cdn.adtidy.org/content/kb/dns/private/router_cudy/cudy17.png) diff --git a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md index cb6b9036e..71dbc6dbd 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md @@ -7,7 +7,7 @@ Ved at opsætte Adgangsindstillinger kan AdGuard DNS beskyttes mod uautoriseret Blokerede forespørgsler vises ikke i Forespørgselsloggen, og tælles ikke med i den samlede kvote. -## Sådan opsættes det +## How to set it up ### Tilladte klienter diff --git a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index 568223a74..993c59b49 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,48 +3,58 @@ title: Forældrekontrol sidebar_position: 5 --- -## Hvad er det +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. -Forældrekontrol er et sæt indstillinger, som giver fleksibilitet til at tilpasse adgangen til bestemte websteder med sensitivt indhold. Man kan bruge denne funktion til at begrænse sine børns adgang til voksenwebsteder, tilpasse søgeforespørgsler, blokere brugen af populære tjenester mv. +## How to set it up -## Sådan opsættes det +You can flexibly configure all features on your servers, including the parental control feature. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. -Man kan fleksibelt opsætte alle funktioner på sine servere, herunder funktionen Forældrekontrol. [I artiklen](private-dns/server-and-settings/server-and-settings.md) kan man gøre sig bekendt med, hvad en "server" er i AdGuard DNS og læse, hvordan man opretter forskellige servere med forskellige sæt af indstillinger. +Then, go to the settings of the selected server and enable the required configurations. -Gå dernæst til indstillingerne for den valgte server og aktivér de ønskede opsætninger. +### Block adult websites -### Blokér voksenwebsteder +Blocks websites with inappropriate and adult content. -Blokerer websteder med upassende og voksenindhold. +![Blocked website \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) -![Blokeret websted \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) +### Safe search -### Sikker søgning +Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -Fjerner upassende resultater fra Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave og Ecosia. +### YouTube restricted mode -![Sikker søgning \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) +Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -### YouTube begrænset tilstand +### Blocked services and websites -Fjerner muligheden for at se og skrive kommentarer under videoer og interagere med 18+ indhold på YouTube. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. -![Begrænset tilstand \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) +![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) -### Blokerede tjenester og websteder +### Block websites by category -AdGuard DNS blokerer adgang til populære tjenester med ét klik. Dette er nyttigt, hvis man ikke ønsker, at tilsluttede enheder besøger f.eks. Instagram og YouTube. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. -![Blokerede tjenester \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) -### Blokér websteder efter kategori +### Pause schedule -Denne funktion muliggør at begrænse adgangen til bestemte webstedskategorier ved at vælge mellem mere end 20 kategorier, herunder _Voksenindhold_, _Spil_, _Bankvirksomhed_ og _Kommunikation_. Blokeres eksempelvis websteder indeholdende information om alkohol, tobak eller stoffer, vil den valgte enhed ikke længere kunne åbne sider, som falder ind under disse kategorier. +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. -![Kategoribaseret blokering \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. -### Planlæg pauser +To set up a pause schedule: -Aktiverer Forældrekontrol på udvalgte dage med et specificeret tidsinterval. F.eks. har man måske tilladt sit barn kun at kigge YouTube-videoer indtil kl. 23:00 på ugens hverdage. Men i weekenderne er YouTube-adgang ikke begrænset. Tilpas tidsplanen som ønsket, og blokér adgang til udvalgte sider i de tidsrum, som ønskes. +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. -![Tidsplan \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. + +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) + +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. + +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. + +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index b88663fbd..acd842dda 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ Disse er yderligere opdelt i underkategorier: - **CDN**: Forespørgsel forbundet til Content Delivery Network (CDN), et verdensomspændende netværk af proxyservere, som øger hastigheden på levering af indhold til slutbrugere - **Øvrige** -### Topvirksomheder +## Topvirksomheder I denne tabel viser vi ikke kun navnene på de mest besøgte/blokerede virksomheder, men også information om, hvilke domæner, som forespørges, eller hvilke domæner, som blokeres mest. diff --git a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..fa8937664 --- /dev/null +++ b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Obligatorisk | Beskrivelse | Example | +| :---------------- | :------------ | :----------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | heltal | Nej | Detected account ID, if any. | `1234` | +| `DnsServerId` | streng | Nej | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | streng | Nej | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | streng | Nej | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | streng | Nej | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | streng | Ja | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | streng | Nej | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | streng | Nej | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | heltal | Ja | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | heltal | Nej | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | heltal | Ja | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | heltal | Ja | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | heltal | Ja | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | heltal | Ja | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | heltal | Ja | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | heltal | Ja | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | heltal | Ja | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | streng | Nej | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Ja | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Ja | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## FAQ + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 1c778c03a..c2e380863 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Forespørgselslog sidebar_position: 5 --- -## Hvad er Forespørgselslog +## What is Query log? -Forespørgselslog er et nyttigt værktøj ved arbejde med AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. Man kan se alle forespørgsler, som er foretaget af ens enheder i den valgte periode og sortere forespørgsler efter status, type, firma, enhed, land. ## Sådan bruges den -Her er, hvad man kan se, og hvad man kan foretage sig i _Forespørgselslog_. +Here’s what you can see and what you can do in _Query log_. ### Detaljeret information om forespørgsler -![Forespørgselsinfo \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Blokering og afblokering af domæner Forespørgsler kan blokeres og afblokeres uden at forlade loggen vha. de tilgængelige værktøjer. -![Afblokér domæne \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Sortering af forespørgsler diff --git a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index 7a8ad143f..871e4a668 100644 --- a/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/da/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS tilbyder en bred vifte af nyttige værktøjer til at overvåge fores - [Trafikdestination](/private-dns/statistics-and-log/traffic-destination.md) - [Virksomheder](/private-dns/statistics-and-log/companies.md) - [Forespørgselslog](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/de/code.json b/i18n/de/code.json index 9916f0ece..a172891c8 100644 --- a/i18n/de/code.json +++ b/i18n/de/code.json @@ -8,11 +8,11 @@ "description": "The site tagline used in meta description" }, "apiChangelog.loading": { - "message": "Loading changelog…", + "message": "Änderungsprotokoll wird geladen…", "description": "Placeholder shown while the API changelog is being loaded" }, "apiChangelog.error": { - "message": "Failed to load the changelog. You can view the original at {link}.", + "message": "Das Änderungsprotokoll konnte nicht geladen werden. Das Original kann unter {link} eingesehen werden.", "description": "Error message shown when the API changelog cannot be loaded. {link} is a link to the original changelog on adguard-dns.io" }, "apiChangelog.versions": { @@ -20,7 +20,7 @@ "description": "Accessible name of the version list sidebar on the API changelog page" }, "apiReference.loading": { - "message": "Loading API reference…", + "message": "API-Referenz wird geladen …", "description": "Placeholder shown while the API reference (Swagger UI) is being loaded" }, "theme.NotFound.title": { @@ -453,31 +453,31 @@ "description": "The placeholder of the input of the DocSearch pop-up modal" }, "theme.colorToggle.ariaLabel.mode.system": { - "message": "system mode", + "message": "Systemmodus", "description": "The name for the system color mode" }, "theme.admonition.warning": { - "message": "warning", + "message": "Warnhinweis", "description": "The default label used for the Warning admonition (:::warning)" }, "theme.DocSidebarItem.expandCategoryAriaLabel": { - "message": "Expand sidebar category '{label}'", + "message": "Seitenleistenkategorie '{label}' öffnen", "description": "The ARIA label to expand the sidebar category" }, "theme.DocSidebarItem.collapseCategoryAriaLabel": { - "message": "Collapse sidebar category '{label}'", + "message": "Seitenleistenkategorie '{label}' schließen", "description": "The ARIA label to collapse the sidebar category" }, "theme.IconExternalLink.ariaLabel": { - "message": "(opens in new tab)", + "message": "(öffnet in einem neuen Tab)", "description": "The ARIA label for the external link icon" }, "theme.navbar.mobileDropdown.collapseButton.expandAriaLabel": { - "message": "Expand the dropdown", + "message": "Auswahlmenü öffnen", "description": "The ARIA label of the button to expand the mobile dropdown navbar item" }, "theme.navbar.mobileDropdown.collapseButton.collapseAriaLabel": { - "message": "Collapse the dropdown", + "message": "Auswahlmenü ausblenden", "description": "The ARIA label of the button to collapse the mobile dropdown navbar item" }, "theme.blog.author.pageTitle": { @@ -485,35 +485,35 @@ "description": "The title of the page for a blog author" }, "theme.blog.authorsList.pageTitle": { - "message": "Authors", + "message": "Autoren", "description": "The title of the authors page" }, "theme.blog.authorsList.viewAll": { - "message": "View all authors", + "message": "Alle Autoren anzeigen", "description": "The label of the link targeting the blog authors page" }, "theme.blog.author.noPosts": { - "message": "This author has not written any posts yet.", + "message": "Dieser Autor hat noch keine Beiträge veröffentlicht.", "description": "The text for authors with 0 blog post" }, "theme.contentVisibility.unlistedBanner.title": { - "message": "Unlisted page", + "message": "Nicht gelistete Seite", "description": "The unlisted content banner title" }, "theme.contentVisibility.unlistedBanner.message": { - "message": "This page is unlisted. Search engines will not index it, and only users having a direct link can access it.", + "message": "Diese Seite ist nicht öffentlich. Suchmaschinen werden sie nicht indexieren, und nur Nutzer mit einem direkten Link können darauf zugreifen.", "description": "The unlisted content banner message" }, "theme.contentVisibility.draftBanner.title": { - "message": "Draft page", + "message": "Entwurf der Seite", "description": "The draft content banner title" }, "theme.contentVisibility.draftBanner.message": { - "message": "This page is a draft. It will only be visible in dev and be excluded from the production build.", + "message": "Diese Seite ist ein Entwurf. Sie ist nur in der Entwicklungsumgebung sichtbar und wird aus der Produktionsversion ausgeschlossen.", "description": "The draft content banner message" }, "theme.docs.DocCard.categoryDescription.plurals": { - "message": "1 item|{count} items", + "message": "1 Artikel|{count} Artikel", "description": "The default description for a category card in the generated index about how many items this category includes" } } diff --git a/i18n/de/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/de/docusaurus-plugin-content-docs/current/general/dns-providers.md index 14f9e1fab..9c3866023 100644 --- a/i18n/de/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/de/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Zu AdGuard hinzufügen](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Zu AdGuard VPN hinzufügen](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Zu AdGuard hinzufügen](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Zu AdGuard VPN hinzufügen](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### Ohne Filterung - -| Protokoll | Adresse | | -| -------------- | ----------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Zu AdGuard hinzufügen](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Zu AdGuard VPN hinzufügen](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Zu AdGuard hinzufügen](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Zu AdGuard VPN hinzufügen](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Sperren von Werbung - -| Protokoll | Adresse | | -| -------------- | ------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Zu AdGuard hinzufügen](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Zu AdGuard VPN hinzufügen](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Zu AdGuard hinzufügen](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Zu AdGuard VPN hinzufügen](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Sperren von Werbung und Malware - -| Protokoll | Adresse | | -| -------------- | ---------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Zu AdGuard hinzufügen](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Zu AdGuard VPN hinzufügen](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Zu AdGuard hinzufügen](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Zu AdGuard VPN hinzufügen](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Sperren von Werbung, Malware und sozialen Medien - -| Protokoll | Adresse | | -| -------------- | -------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Zu AdGuard hinzufügen](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Zu AdGuard VPN hinzufügen](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Zu AdGuard hinzufügen](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Zu AdGuard VPN hinzufügen](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Sperren von Werbung + Malware + Erotik + Glücksspiel - -| Protokoll | Adresse | | -| -------------- | ------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Zu AdGuard hinzufügen](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Zu AdGuard VPN hinzufügen](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Zu AdGuard hinzufügen](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Zu AdGuard VPN hinzufügen](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Sperren von Werbung + Malware + Erotik + Glücksspiel + Soziale Medien - -| Protokoll | Adresse | | -| -------------- | --------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Zu AdGuard hinzufügen](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Zu AdGuard VPN hinzufügen](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Zu AdGuard hinzufügen](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Zu AdGuard VPN hinzufügen](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### Ungesichert -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protokoll | Adresse | | | -------------- | ----------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/de/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/de/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index 548dd9391..0218f363c 100644 --- a/i18n/de/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/de/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,48 +3,58 @@ title: Kindersicherung sidebar_position: 5 --- -## Was ist das +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. -Kindersicherung ist eine Reihe von Einstellungen, die Ihnen die Flexibilität bieten, den Zugriff auf bestimmte Websites mit sensiblen Inhalt anzupassen. Diese Funktion können Sie verwenden, um den Zugriff Ihrer Kinder auf Websites mit Inhalten für Erwachsene einzuschränken, Suchabfragen anzupassen, die Nutzung beliebter Dienste zu blockieren und mehr. +## How to set it up -## Kindersicherung einrichten +You can flexibly configure all features on your servers, including the parental control feature. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. -Sie können alle Funktionen flexibel auf Ihren Servern konfigurieren, einschließlich der Kindersicherungsfunktion. [Im entsprechenden Artikel](private-dns/server-and-settings/server-and-settings.md) können Sie sich damit vertraut machen, was ein Server in AdGuard DNS ist, und erfahren, wie Sie verschiedene Server mit unterschiedlichen Einstellungen erstellen. +Then, go to the settings of the selected server and enable the required configurations. -Gehen Sie anschließend zu den Einstellungen des ausgewählten Servers und aktivieren Sie die erforderlichen Konfigurationen. +### Block adult websites -### Websites für Erwachsene blockieren +Blocks websites with inappropriate and adult content. -Blockiert Websites mit unangemessenen und nicht jugendfreien Inhalten. +![Blocked website \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) -![Blockierte Website \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) +### Safe search -### Sichere Suche +Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -Entfernt unangemessene Ergebnisse von Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave und Ecosia. +### YouTube restricted mode -![Sichere Suche \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) +Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -### Eingeschränkter Modus für YouTube +### Blocked services and websites -Entfernt die Option, Kommentare unter Videos anzusehen und zu posten sowie mit Inhalten ab 18 Jahren auf YouTube zu interagieren. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. -![Eingeschränkter Modus \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) +![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) -### Gesperrte Dienste und Websites +### Block websites by category -AdGuard DNS sperrt den Zugriff auf beliebte Dienste mit einem Klick. Das ist nützlich, wenn Sie nicht möchten, dass verbundene Geräte z. B. Instagram und YouTube besuchen. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. -![Gesperrte Dienste \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) -### Block websites by category +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. -This feature lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### Abschaltzeit einstellen +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -Mit dieser Funktion kann die Kindersicherung an ausgewählten Tagen mit einem bestimmten Zeitintervall aktiviert werden. Vielleicht haben Sie Ihrem Kind zum Beispiel erlaubt, YouTube-Videos nur bis 23:00 Uhr an Werktagen anzusehen. Aber an Wochenenden ist dieser Zugriff nicht eingeschränkt. Passen Sie den Zeitplan nach Ihren Wünschen an und blockieren Sie den Zugriff auf ausgewählte Websites zu den gewünschten Stunden. +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![Zeitplan \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index e79c9e4ba..4cedb0986 100644 --- a/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ Diese sind weiter in Unterkategorien unterteilt: - **CDN**: Anfrage im Zusammenhang mit Content Delivery Network (CDN), einem weltweiten Netzwerk von Proxy-Servern, das die Bereitstellung von Inhalten an Endnutzer beschleunigt - **Sonstiges** -### Top Unternehmen +## Top Unternehmen In dieser Tabelle zeigen wir nicht nur die Namen der meistbesuchten oder meistgesperrten Unternehmen, sondern auch Informationen darüber, von welchen Domains Anfragen gesendet oder welche Domains am häufigsten gesperrt werden. diff --git a/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..92d0ddc29 --- /dev/null +++ b/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Erforderlich | Beschreibung | Example | +| :---------------- | :------------ | :----------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | Nein | Detected account ID, if any. | `1234` | +| `DnsServerId` | string | Nein | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | string | Nein | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | string | Nein | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | string | Nein | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | string | Ja | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | string | Nein | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | string | Nein | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Ja | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | Nein | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Ja | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Ja | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Ja | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Ja | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Ja | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Ja | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Ja | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | string | Nein | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Ja | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Ja | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## FAQ + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 49fc993f2..160bf074b 100644 --- a/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Anfragenprotokoll sidebar_position: 5 --- -## Anfragenprotokoll: Überblick +## What is Query log? -Das Anfragenprotokoll ist ein nützliches Tool für die Arbeit mit AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. Es ermöglicht Ihnen, alle Anfragen Ihrer Geräte während des ausgewählten Zeitraums einzusehen und Anfragen nach Status, Typ, Unternehmen, Gerät und Land zu sortieren. ## Kurzanleitung -Hier ist, was Sie im _Anfragenprotokoll_ sehen und was Sie tun können. +Here’s what you can see and what you can do in _Query log_. ### Detaillierte Informationen zu Anfragen -![Anfragen-Informationen \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Sperren und Entsperren von Domänen Mithilfe der verfügbaren Tools können Anfragen gesperrt und entsperrt werden, ohne das Protokoll zu verlassen. -![Domain entsperren \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Sortieren von Anfragen diff --git a/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index b0100f1a6..cadbe00ac 100644 --- a/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/de/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS bietet eine breite Palette nützlicher Tools zur Überwachung von An - [Traffic-Zielort](/private-dns/statistics-and-log/traffic-destination.md) - [Unternehmen](/private-dns/statistics-and-log/companies.md) - [Anfragenprotokoll](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/es/code.json b/i18n/es/code.json index 7d05c62f7..a41076026 100644 --- a/i18n/es/code.json +++ b/i18n/es/code.json @@ -8,51 +8,51 @@ "description": "The site tagline used in meta description" }, "apiChangelog.loading": { - "message": "Loading changelog…", + "message": "Cargando el registro de cambios…", "description": "Placeholder shown while the API changelog is being loaded" }, "apiChangelog.error": { - "message": "Failed to load the changelog. You can view the original at {link}.", + "message": "No se pudo cargar el registro de cambios. Puedes consultar el original en {link}.", "description": "Error message shown when the API changelog cannot be loaded. {link} is a link to the original changelog on adguard-dns.io" }, "apiChangelog.versions": { - "message": "Versions", + "message": "Versiones", "description": "Accessible name of the version list sidebar on the API changelog page" }, "apiReference.loading": { - "message": "Loading API reference…", + "message": "Cargando la referencia de la API…", "description": "Placeholder shown while the API reference (Swagger UI) is being loaded" }, "theme.NotFound.title": { - "message": "Page Not Found", + "message": "Página no encontrada", "description": "The title of the 404 page" }, "theme.NotFound.p1": { - "message": "We could not find what you were looking for.", + "message": "No pudimos encontrar lo que estabas buscando.", "description": "The first paragraph of the 404 page" }, "theme.NotFound.p2": { - "message": "Please contact the owner of the site that linked you to the original URL and let them know their link is broken.", + "message": "Ponte en contacto con el propietario del sitio que te dirigió a la URL original e infórmale de que su enlace no funciona.", "description": "The 2nd paragraph of the 404 page" }, "theme.AnnouncementBar.closeButtonAriaLabel": { - "message": "Close", + "message": "Cerrar", "description": "The ARIA label for close button of announcement bar" }, "theme.blog.paginator.navAriaLabel": { - "message": "Blog list page navigation", + "message": "Navegar en la lista de página del blog", "description": "The ARIA label for the blog pagination" }, "theme.blog.paginator.newerEntries": { - "message": "Newer Entries", + "message": "Entradas más recientes", "description": "The label used to navigate to the newer blog posts page (previous page)" }, "theme.blog.paginator.olderEntries": { - "message": "Older Entries", + "message": "Entradas antiguas", "description": "The label used to navigate to the older blog posts page (next page)" }, "theme.blog.post.readingTime.plurals": { - "message": "One min read|{readingTime} min read", + "message": "Un minuto de lectura| {readingTime} min. de lectura", "description": "Pluralized label for \"{readingTime} min read\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.tags.tagsListLabel": { @@ -60,167 +60,167 @@ "description": "The label alongside a tag list" }, "theme.blog.post.readMore": { - "message": "Read More", + "message": "Más información", "description": "The label used in blog post item excerpts to link to full blog posts" }, "theme.blog.post.paginator.navAriaLabel": { - "message": "Blog post page navigation", + "message": "Navegación en la página del blog", "description": "The ARIA label for the blog posts pagination" }, "theme.blog.post.paginator.newerPost": { - "message": "Newer Post", + "message": "Entrada más reciente", "description": "The blog post button label to navigate to the newer/previous post" }, "theme.blog.post.paginator.olderPost": { - "message": "Older Post", + "message": "Entrada más antigua", "description": "The blog post button label to navigate to the older/next post" }, "theme.blog.sidebar.navAriaLabel": { - "message": "Recent blog posts navigation", + "message": "Navegación por las últimas entradas del blog", "description": "The ARIA label for recent posts in the blog sidebar" }, "theme.tags.tagsPageTitle": { - "message": "Tags", + "message": "Etiquetas", "description": "The title of the tag list page" }, "theme.blog.post.plurals": { - "message": "One post|{count} posts", + "message": "Una publicación|{count} publicación", "description": "Pluralized label for \"{count} posts\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.blog.tagTitle": { - "message": "{nPosts} tagged with \"{tagName}\"", + "message": "{nPosts} etiquetado con \"{tagName}\"", "description": "The title of the page for a blog tag" }, "theme.tags.tagsPageLink": { - "message": "View All Tags", + "message": "Ver todas las etiquetas", "description": "The label of the link targeting the tag list page" }, "theme.CodeBlock.copyButtonAriaLabel": { - "message": "Copy code to clipboard", + "message": "Copiar el código en el portapapeles", "description": "The ARIA label for copy code blocks button" }, "theme.CodeBlock.copied": { - "message": "Copied", + "message": "Copiado", "description": "The copied button label on code blocks" }, "theme.CodeBlock.copy": { - "message": "Copy", + "message": "Copiar", "description": "The copy button label on code blocks" }, "theme.docs.sidebar.expandButtonTitle": { - "message": "Expand sidebar", + "message": "Ampliar la barra lateral", "description": "The ARIA label and title attribute for expand button of doc sidebar" }, "theme.docs.sidebar.expandButtonAriaLabel": { - "message": "Expand sidebar", + "message": "Ampliar la barra lateral", "description": "The ARIA label and title attribute for expand button of doc sidebar" }, "theme.docs.paginator.navAriaLabel": { - "message": "Docs pages navigation", + "message": "Navegar por las páginas de los documentos", "description": "The ARIA label for the docs pagination" }, "theme.docs.paginator.previous": { - "message": "Previous", + "message": "Anteriormente", "description": "The label used to navigate to the previous doc" }, "theme.docs.paginator.next": { - "message": "Next", + "message": "Siguiente", "description": "The label used to navigate to the next doc" }, "theme.docs.sidebar.collapseButtonTitle": { - "message": "Collapse sidebar", + "message": "Colapsar la barra lateral", "description": "The title attribute for collapse button of doc sidebar" }, "theme.docs.sidebar.collapseButtonAriaLabel": { - "message": "Collapse sidebar", + "message": "Colapsar la barra lateral", "description": "The title attribute for collapse button of doc sidebar" }, "theme.docs.versions.unreleasedVersionLabel": { - "message": "This is unreleased documentation for {siteTitle} {versionLabel} version.", + "message": "Se trata de una documentación inédita {siteTitle} {versionLabel} para la versión.", "description": "The label used to tell the user that he's browsing an unreleased doc version" }, "theme.docs.versions.unmaintainedVersionLabel": { - "message": "This is documentation for {siteTitle} {versionLabel}, which is no longer actively maintained.", + "message": "Esta es la documentación de {siteTitle} {versionLabel}, que ya no se mantiene activamente.", "description": "The label used to tell the user that he's browsing an unmaintained doc version" }, "theme.docs.versions.latestVersionSuggestionLabel": { - "message": "For up-to-date documentation, see the {latestVersionLink} ({versionLabel}).", + "message": "Para obtener documentación actualizada, consulta {latestVersionLink} ({versionLabel}).", "description": "The label used to tell the user to check the latest version" }, "theme.docs.versions.latestVersionLinkLabel": { - "message": "latest version", + "message": "última versión", "description": "The label used for the latest version suggestion link label" }, "theme.common.editThisPage": { - "message": "Edit this page", + "message": "Editar esta página", "description": "The link label to edit the current page" }, "theme.common.headingLinkTitle": { - "message": "Direct link to heading", + "message": "Enlace directo al encabezado", "description": "Title for link to heading" }, "theme.lastUpdated.atDate": { - "message": " on {date}", + "message": " en {date}", "description": "The words used to describe on which date a page has been last updated" }, "theme.lastUpdated.byUser": { - "message": " by {user}", + "message": " por {user}", "description": "The words used to describe by who the page has been last updated" }, "theme.lastUpdated.lastUpdatedAtBy": { - "message": "Last updated{atDate}{byUser}", + "message": "Última actualización{atDate}{byUser}", "description": "The sentence used to display when a page has been last updated, and by who" }, "theme.navbar.mobileSidebarSecondaryMenu.backButtonLabel": { - "message": "← Back to main menu", + "message": "← Volver al menú principal", "description": "The label of the back button to return to main menu, inside the mobile navbar sidebar secondary menu (notably used to display the docs sidebar)" }, "theme.common.skipToMainContent": { - "message": "Skip to main content", + "message": "Saltar al contenido principal", "description": "The skip to content label used for accessibility, allowing to rapidly navigate to main content with keyboard tab/enter navigation" }, "theme.TOCCollapsible.toggleButtonLabel": { - "message": "On this page", + "message": "En esta página", "description": "The label used by the button on the collapsible TOC component" }, "theme.ErrorPageContent.title": { - "message": "This page crashed.", + "message": "Esta página se ha colapsado.", "description": "The title of the fallback page when the page crashed" }, "theme.ErrorPageContent.tryAgain": { - "message": "Try again", + "message": "Vuelve a intentarlo", "description": "The label of the button to try again rendering when the React error boundary captures an error" }, "theme.BackToTopButton.buttonAriaLabel": { - "message": "Scroll back to top", + "message": "Volver al principio", "description": "The ARIA label for the back to top button" }, "theme.blog.archive.title": { - "message": "Archive", + "message": "Archivo", "description": "The page & hero title of the blog archive page" }, "theme.blog.archive.description": { - "message": "Archive", + "message": "Archivo", "description": "The page & hero description of the blog archive page" }, "theme.blog.post.readMoreLabel": { - "message": "Read more about {title}", + "message": "Leer más sobre {title}", "description": "The ARIA label for the link to full blog posts from excerpts" }, "theme.colorToggle.ariaLabel": { - "message": "Switch between dark and light mode (currently {mode})", + "message": "Cambiar entre el modo oscuro y el modo claro (actualmente {mode})", "description": "The ARIA label for the color mode toggle" }, "theme.colorToggle.ariaLabel.mode.dark": { - "message": "dark mode", + "message": "modo oscuro", "description": "The name for the dark color mode" }, "theme.colorToggle.ariaLabel.mode.light": { - "message": "light mode", + "message": "modo claro", "description": "The name for the light color mode" }, "theme.docs.breadcrumbs.home": { - "message": "Home page", + "message": "Página principal", "description": "The ARIA label for the home page in the breadcrumbs" }, "theme.docs.breadcrumbs.navAriaLabel": { @@ -228,256 +228,256 @@ "description": "The ARIA label for the breadcrumbs" }, "theme.docs.DocCard.categoryDescription": { - "message": "{count} items", + "message": "{count} elementos", "description": "The default description for a category card in the generated index about how many items this category includes" }, "theme.docs.tagDocListPageTitle.nDocsTagged": { - "message": "One doc tagged|{count} docs tagged", + "message": "Un documento etiquetado|{count} documentos etiquetados", "description": "Pluralized label for \"{count} docs tagged\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.docs.tagDocListPageTitle": { - "message": "{nDocsTagged} with \"{tagName}\"", + "message": "{nDocsTagged} documentos etiquetados con \"{tagName}\"", "description": "The title of the page for a docs tag" }, "theme.docs.versionBadge.label": { - "message": "Version: {versionLabel}" + "message": "Versión: {versionLabel}" }, "theme.navbar.mobileVersionsDropdown.label": { - "message": "Versions", + "message": "Versiones", "description": "The label for the navbar versions dropdown on mobile view" }, "theme.CodeBlock.wordWrapToggle": { - "message": "Toggle word wrap", + "message": "Alternar ajuste de palabras", "description": "The title attribute for toggle word wrapping button of code block lines" }, "theme.DocSidebarItem.toggleCollapsedCategoryAriaLabel": { - "message": "Toggle the collapsible sidebar category '{label}'", + "message": "Alternar la categoría de barra lateral plegable '{label}'", "description": "The ARIA label to toggle the collapsible sidebar category" }, "theme.navbar.mobileLanguageDropdown.label": { - "message": "Languages", + "message": "Idiomas", "description": "The label for the mobile language switcher dropdown" }, "theme.IdealImageMessage.loading": { - "message": "Loading...", + "message": "Cargando...", "description": "When the full-scale image is loading" }, "theme.IdealImageMessage.load": { - "message": "Click to load{sizeMessage}", + "message": "Haz clic para cargar{sizeMessage}", "description": "To prompt users to load the full image. sizeMessage is a parenthesized size figure." }, "theme.IdealImageMessage.offline": { - "message": "Your browser is offline. Image not loaded", + "message": "Tu navegador está sin conexión. La imagen no se ha cargado", "description": "When the user is viewing an offline document" }, "theme.IdealImageMessage.404error": { - "message": "404. Image not found", + "message": "404. Imagen no encontrada", "description": "When the image is not found" }, "theme.IdealImageMessage.error": { - "message": "Error. Click to reload", + "message": "Error. Haz clic para volver a cargar", "description": "When the image fails to load for unknown error" }, "theme.SearchBar.noResultsText": { - "message": "No results" + "message": "Sin resultados" }, "theme.SearchBar.seeAll": { - "message": "See all results" + "message": "Ver todos los resultados" }, "theme.SearchBar.label": { - "message": "Search", + "message": "Buscar", "description": "The ARIA label and placeholder for search button" }, "theme.SearchPage.existingResultsTitle": { - "message": "Search results for \"{query}\"", + "message": "Resultados de búsqueda para \"{query}\"", "description": "The search page title for non-empty query" }, "theme.SearchPage.emptyResultsTitle": { - "message": "Search the documentation", + "message": "Buscar en la documentación", "description": "The search page title for empty query" }, "theme.SearchPage.documentsFound.plurals": { - "message": "One document found|{count} documents found", + "message": "Un documento encontrado|{count} documentos encontrados", "description": "Pluralized label for \"{count} documents found\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.SearchPage.noResultsText": { - "message": "No documents were found", + "message": "No se encontraron documentos", "description": "The paragraph for empty search result" }, "theme.SearchPage.inputPlaceholder": { - "message": "Type your search here", + "message": "Escribe tu búsqueda aquí", "description": "The placeholder for search page input" }, "theme.SearchPage.inputLabel": { - "message": "Search", + "message": "Buscar", "description": "The ARIA label for search page input" }, "theme.SearchPage.algoliaLabel": { - "message": "Search by Typesense", + "message": "Búsqueda con Typesense", "description": "The ARIA label for Typesense mention" }, "theme.SearchPage.fetchingNewResults": { - "message": "Fetching new results...", + "message": "Buscando nuevos resultados...", "description": "The paragraph for fetching new search results" }, "theme.admonition.note": { - "message": "note", + "message": "nota", "description": "The default label used for the Note admonition (:::note)" }, "theme.admonition.tip": { - "message": "tip", + "message": "consejo", "description": "The default label used for the Tip admonition (:::tip)" }, "theme.admonition.danger": { - "message": "danger", + "message": "peligro", "description": "The default label used for the Danger admonition (:::danger)" }, "theme.admonition.info": { - "message": "info", + "message": "información", "description": "The default label used for the Info admonition (:::info)" }, "theme.admonition.caution": { - "message": "caution", + "message": "precaución", "description": "The default label used for the Caution admonition (:::caution)" }, "theme.NavBar.navAriaLabel": { - "message": "Main", + "message": "Principal", "description": "The ARIA label for the main navigation" }, "theme.docs.sidebar.navAriaLabel": { - "message": "Docs sidebar", + "message": "Barra lateral de documentos", "description": "The ARIA label for the sidebar navigation" }, "theme.docs.sidebar.closeSidebarButtonAriaLabel": { - "message": "Close navigation bar", + "message": "Cerrar la barra de navegación", "description": "The ARIA label for close button of mobile sidebar" }, "theme.docs.sidebar.toggleSidebarButtonAriaLabel": { - "message": "Toggle navigation bar", + "message": "Alternar barra de navegación", "description": "The ARIA label for hamburger menu button of mobile navigation" }, "theme.SearchPage.typesenseLabel": { - "message": "Search by Typesense", + "message": "Búsqueda con Typesense", "description": "The ARIA label for Typesense mention" }, "theme.SearchModal.searchBox.resetButtonTitle": { - "message": "Clear the query", + "message": "Borrar la consulta", "description": "The label and ARIA label for search box reset button" }, "theme.SearchModal.searchBox.cancelButtonText": { - "message": "Cancel", + "message": "Cancelar", "description": "The label and ARIA label for search box cancel button" }, "theme.SearchModal.startScreen.recentSearchesTitle": { - "message": "Recent", + "message": "Reciente", "description": "The title for recent searches" }, "theme.SearchModal.startScreen.noRecentSearchesText": { - "message": "No recent searches", + "message": "No hay búsquedas recientes", "description": "The text when no recent searches" }, "theme.SearchModal.startScreen.saveRecentSearchButtonTitle": { - "message": "Save this search", + "message": "Guardar esta búsqueda", "description": "The label for save recent search button" }, "theme.SearchModal.startScreen.removeRecentSearchButtonTitle": { - "message": "Remove this search from history", + "message": "Remover esta búsqueda del historial", "description": "The label for remove recent search button" }, "theme.SearchModal.startScreen.favoriteSearchesTitle": { - "message": "Favorite", + "message": "Favorito", "description": "The title for favorite searches" }, "theme.SearchModal.startScreen.removeFavoriteSearchButtonTitle": { - "message": "Remove this search from favorites", + "message": "Remover esta búsqueda de favoritos", "description": "The label for remove favorite search button" }, "theme.SearchModal.errorScreen.titleText": { - "message": "Unable to fetch results", + "message": "Incapaz de obtener resultados", "description": "The title for error screen of search modal" }, "theme.SearchModal.errorScreen.helpText": { - "message": "You might want to check your network connection.", + "message": "Es posible que desee verificar su conexión a Internet.", "description": "The help text for error screen of search modal" }, "theme.SearchModal.footer.selectText": { - "message": "to select", + "message": "para seleccionar", "description": "The explanatory text of the action for the enter key" }, "theme.SearchModal.footer.selectKeyAriaLabel": { - "message": "Enter key", + "message": "Tecla enter", "description": "The ARIA label for the Enter key button that makes the selection" }, "theme.SearchModal.footer.navigateText": { - "message": "to navigate", + "message": "para navegar", "description": "The explanatory text of the action for the Arrow up and Arrow down key" }, "theme.SearchModal.footer.navigateUpKeyAriaLabel": { - "message": "Arrow up", + "message": "Flecha hacia arriba", "description": "The ARIA label for the Arrow up key button that makes the navigation" }, "theme.SearchModal.footer.navigateDownKeyAriaLabel": { - "message": "Arrow down", + "message": "Flecha hacia abajo", "description": "The ARIA label for the Arrow down key button that makes the navigation" }, "theme.SearchModal.footer.closeText": { - "message": "to close", + "message": "para cerrar", "description": "The explanatory text of the action for Escape key" }, "theme.SearchModal.footer.closeKeyAriaLabel": { - "message": "Escape key", + "message": "Tecla esc", "description": "The ARIA label for the Escape key button that close the modal" }, "theme.SearchModal.footer.searchByText": { - "message": "Search by", + "message": "Buscar por", "description": "The text explain that the search is making by Algolia" }, "theme.SearchModal.noResultsScreen.noResultsText": { - "message": "No results for", + "message": "No hay resultados para", "description": "The text explains that there are no results for the following search" }, "theme.SearchModal.noResultsScreen.suggestedQueryText": { - "message": "Try searching for", + "message": "Intente buscar", "description": "The text for the suggested query when no results are found for the following search" }, "theme.SearchModal.noResultsScreen.reportMissingResultsText": { - "message": "Believe this query should return results?", + "message": "¿Crees que esta consulta debería mostrar resultados?", "description": "The text for the question where the user thinks there are missing results" }, "theme.SearchModal.noResultsScreen.reportMissingResultsLinkText": { - "message": "Let us know.", + "message": "Déjanos saber.", "description": "The text for the link to report missing results" }, "theme.SearchModal.placeholder": { - "message": "Search docs", + "message": "Buscar documentos", "description": "The placeholder of the input of the DocSearch pop-up modal" }, "theme.colorToggle.ariaLabel.mode.system": { - "message": "system mode", + "message": "modo del sistema", "description": "The name for the system color mode" }, "theme.admonition.warning": { - "message": "warning", + "message": "advertencia", "description": "The default label used for the Warning admonition (:::warning)" }, "theme.DocSidebarItem.expandCategoryAriaLabel": { - "message": "Expand sidebar category '{label}'", + "message": "Expandir la categoría de la barra lateral '{label}'", "description": "The ARIA label to expand the sidebar category" }, "theme.DocSidebarItem.collapseCategoryAriaLabel": { - "message": "Collapse sidebar category '{label}'", + "message": "Contraer la categoría de la barra lateral '{label}'", "description": "The ARIA label to collapse the sidebar category" }, "theme.IconExternalLink.ariaLabel": { - "message": "(opens in new tab)", + "message": "(se abre en una pestaña nueva)", "description": "The ARIA label for the external link icon" }, "theme.navbar.mobileDropdown.collapseButton.expandAriaLabel": { - "message": "Expand the dropdown", + "message": "Expandir el menú desplegable", "description": "The ARIA label of the button to expand the mobile dropdown navbar item" }, "theme.navbar.mobileDropdown.collapseButton.collapseAriaLabel": { - "message": "Collapse the dropdown", + "message": "Contraer el menú desplegable", "description": "The ARIA label of the button to collapse the mobile dropdown navbar item" }, "theme.blog.author.pageTitle": { @@ -485,35 +485,35 @@ "description": "The title of the page for a blog author" }, "theme.blog.authorsList.pageTitle": { - "message": "Authors", + "message": "Autores", "description": "The title of the authors page" }, "theme.blog.authorsList.viewAll": { - "message": "View all authors", + "message": "Ver todos los autores", "description": "The label of the link targeting the blog authors page" }, "theme.blog.author.noPosts": { - "message": "This author has not written any posts yet.", + "message": "Este autor aún no ha escrito ninguna publicación.", "description": "The text for authors with 0 blog post" }, "theme.contentVisibility.unlistedBanner.title": { - "message": "Unlisted page", + "message": "Página no listada", "description": "The unlisted content banner title" }, "theme.contentVisibility.unlistedBanner.message": { - "message": "This page is unlisted. Search engines will not index it, and only users having a direct link can access it.", + "message": "Esta página no está listada. Los motores de búsqueda no la indexarán y solo los usuarios que tengan un enlace directo podrán acceder a ella.", "description": "The unlisted content banner message" }, "theme.contentVisibility.draftBanner.title": { - "message": "Draft page", + "message": "Página en borrador", "description": "The draft content banner title" }, "theme.contentVisibility.draftBanner.message": { - "message": "This page is a draft. It will only be visible in dev and be excluded from the production build.", + "message": "Esta página es un borrador. Solo será visible en el entorno de desarrollo y se excluirá de la compilación de producción.", "description": "The draft content banner message" }, "theme.docs.DocCard.categoryDescription.plurals": { - "message": "1 item|{count} items", + "message": "1 elemento|{count} elementos", "description": "The default description for a category card in the generated index about how many items this category includes" } } diff --git a/i18n/es/docusaurus-plugin-content-docs/current.json b/i18n/es/docusaurus-plugin-content-docs/current.json index 51652e4b8..2d92c5d17 100644 --- a/i18n/es/docusaurus-plugin-content-docs/current.json +++ b/i18n/es/docusaurus-plugin-content-docs/current.json @@ -1,6 +1,6 @@ { "version.label": { - "message": "Next", + "message": "Siguiente", "description": "The label for version current" }, "sidebar.sidebar.category.General": { diff --git a/i18n/es/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/es/docusaurus-plugin-content-docs/current/general/dns-providers.md index 9360a8f3f..fa5f95c10 100644 --- a/i18n/es/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/es/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### Sin filtrado - -| Protocolo | Dirección | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| Protocolo | Dirección | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Ad + malware blocking - -| Protocolo | Dirección | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Ad + malware + social media blocking - -| Protocolo | Dirección | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Ad + malware + adult + gambling blocking - -| Protocolo | Dirección | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Ad + malware + adult + gambling + social media blocking - -| Protocolo | Dirección | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### Unsecured -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protocolo | Dirección | | | -------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/es/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md b/i18n/es/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md index 67807561f..0aa3fddbc 100644 --- a/i18n/es/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md +++ b/i18n/es/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md @@ -9,7 +9,7 @@ DNS-over-HTTPS con autenticación permite que configures un nombre de usuario y Esto ayuda a prevenir que usuarios no autorizados accedan a él y mejora la seguridad. Además, puedes restringir el uso de otros protocolos para perfiles específicos. Esta función es particularmente útil cuando la dirección de tu servidor DNS es conocida por otros. Al agregar una contraseña, puedes bloquear el acceso y asegurarte de que solo tú puedas usarlo. -## Cómo configurarlo +## How to set it up :::note Compatibilidad diff --git a/i18n/es/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md b/i18n/es/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md index 11b4e51ad..284e6728b 100644 --- a/i18n/es/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md +++ b/i18n/es/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md @@ -7,7 +7,7 @@ Al configurar la configuración de acceso, podrás proteger tu AdGuard DNS de ac Las peticiones bloqueadas no se mostrarán en el registro de consultas y no se cuentan en el límite total. -## Cómo configurarlo +## How to set it up ### Clientes permitidos diff --git a/i18n/es/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/es/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index 800317634..89cff75ea 100644 --- a/i18n/es/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/es/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,48 +3,58 @@ title: Control parental sidebar_position: 5 --- -## ¿Qué es? +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. -Parental control is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. +## How to set it up -## Cómo configurarlo +You can flexibly configure all features on your servers, including the parental control feature. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. -Puedes configurar todas las funciones en tus servidores de forma flexible, incluyendo la función de control parental. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. +Then, go to the settings of the selected server and enable the required configurations. -Luego, ve a la configuración del servidor seleccionado y habilita las configuraciones requeridas. +### Block adult websites -### Bloquear sitios web para adultos +Blocks websites with inappropriate and adult content. -Bloquea sitios web con contenido inapropiado y para adultos. +![Blocked website \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) -![Sitio web bloqueado \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) +### Safe search -### Búsqueda segura +Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -Elimina resultados inapropiados de Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave y Ecosia. +### YouTube restricted mode -![Búsqueda segura \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) +Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -### Modo restringido de YouTube +### Blocked services and websites -Elimina la opción de ver y publicar comentarios en videos e interactuar con contenido 18+ en YouTube. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. -![Modo restringido \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) +![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) -### Servicios y sitios web bloqueados +### Block websites by category -AdGuard DNS bloquea el acceso a servicios populares con un solo clic. It’s useful if you don’t want connected devices to visit Instagram and YouTube, for example. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. -![Servicios bloqueados \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) -### Block websites by category +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. -This feature lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### Programar tiempo de descanso +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -Habilita el control parental en días seleccionados con un intervalo de tiempo especificado. Por ejemplo, es posible que hayas permitido que tu hijo vea videos de YouTube solo hasta las 23:00 horas en días de semana. Pero los fines de semana, este acceso no está restringido. Personaliza el horario a tu gusto y bloquea el acceso a sitios seleccionados durante las horas que desees. +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![Horario \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index c80c81e1c..021178285 100644 --- a/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ Estas se dividen además en subcategorías: - **CDN**: petición conectada a la Red de Entrega de Contenidos (CDN), una red mundial de servidores proxy que acelera la entrega de contenido a los usuarios finales - **Otro** -### Principales empresas +## Principales empresas En esta tabla, no solo mostramos los nombres de las empresas más visitadas o más bloqueadas, sino que también mostramos información sobre qué dominios están siendo consultados o cuáles están siendo bloqueados más. diff --git a/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..8d397aaf2 --- /dev/null +++ b/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Requerido | Descripción | Example | +| :---------------- | :------------ | :-------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | No | Detected account ID, if any. | `1234` | +| `DnsServerId` | linha | No | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | linha | No | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | linha | No | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | linha | No | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | linha | Sí | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | linha | No | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | linha | No | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Sí | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | No | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Sí | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Sí | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Sí | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Sí | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Sí | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Sí | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Sí | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | linha | No | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Sí | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Sí | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## Preguntas frecuentes + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 7ecb2a7d7..ec1a1e3d3 100644 --- a/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Registro de consultas sidebar_position: 5 --- -## ¿Qué es el Registro de consultas? +## What is Query log? -El registro de consultas es una herramienta útil para trabajar con AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. Te permite ver todas las peticiones realizadas por tus dispositivos durante el período de tiempo seleccionado y ordenar las peticiones por estado, tipo, empresa, dispositivo, país. ## Cómo utilizarlo -Here’s what you can see and what you can do in the _Query log_. +Here’s what you can see and what you can do in _Query log_. ### Información detallada sobre las peticiones -![Información de peticiones \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Bloqueo y desbloqueo de dominios Las peticiones pueden ser bloqueadas y desbloqueadas sin salir del registro, utilizando las herramientas disponibles. -![Desbloquear dominio \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Ordenar peticiones diff --git a/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index 7200490ad..122300201 100644 --- a/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/es/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS proporciona una amplia gama de herramientas útiles para monitorear - [Destino del tráfico](/private-dns/statistics-and-log/traffic-destination.md) - [Empresas](/private-dns/statistics-and-log/companies.md) - [Registro de consultas](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/fi/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/fi/docusaurus-plugin-content-docs/current/general/dns-providers.md index 614bfba98..15348bd48 100644 --- a/i18n/fi/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/fi/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### Non-filtering - -| Protocol | Address | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| Protocol | Address | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Ad + malware blocking - -| Protocol | Address | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Ad + malware + social media blocking - -| Protocol | Address | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Ad + malware + adult + gambling blocking - -| Protocol | Address | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Ad + malware + adult + gambling + social media blocking - -| Protocol | Address | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### Unsecured -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protocol | Address | | | -------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index cd2a4ad76..143c85ffa 100644 --- a/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,9 +3,7 @@ title: Parental control sidebar_position: 5 --- -## What is it - -Parental control is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. ## How to set it up @@ -23,28 +21,40 @@ Blocks websites with inappropriate and adult content. Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -![Safe search \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) - ### YouTube restricted mode Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -![Restricted mode \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) - ### Blocked services and websites -AdGuard DNS blocks access to popular services with one click. It’s useful if you don’t want connected devices to visit Instagram and YouTube, for example. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. ![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) ### Block websites by category -This feature lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. + +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) + +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. + +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### Schedule off time +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -Enables parental controls on selected days with a specified time interval. For example, you may have allowed your child to watch YouTube videos only until 23:00 on weekdays. But on weekends, this access is not restricted. Customize the schedule to your liking and block access to selected sites during the hours you want. +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![Schedule \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index b21375a03..1e626b858 100644 --- a/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ These are further divided into sub-categories: - **CDN**: request connected to Content Delivery Network (CDN), a worldwide network of proxy servers that speeds the delivery of content to end users - **Other** -### Top companies +## Top companies In this table, we not only show the names of the most visited or most blocked companies, but also display information about which domains are being requested from or which domains are being blocked the most. diff --git a/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..ffcab300d --- /dev/null +++ b/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Required | Description | Example | +| :---------------- | :------------ | :------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | No | Detected account ID, if any. | `1234` | +| `DnsServerId` | string | No | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | string | No | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | string | No | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | string | No | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | string | Yes | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | string | No | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | string | No | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Yes | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | No | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Yes | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Yes | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Yes | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Yes | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Yes | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Yes | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Yes | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | string | No | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Yes | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Yes | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## UKK + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 90ecc6874..3367affbe 100644 --- a/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Query log sidebar_position: 5 --- -## What is Query log +## What is Query log? -Query log is a useful tool for working with AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. It allows you to view all requests made by your devices during the selected time period and sort requests by status, type, company, device, country. ## How to use it -Here’s what you can see and what you can do in the _Query log_. +Here’s what you can see and what you can do in _Query log_. ### Detailed information on requests -![Requests info \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Blocking and unblocking domains Requests can be blocked and unblocked without leaving the log, using the available tools. -![Unblock domain \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Sorting requests diff --git a/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index b9047787e..4281c19bb 100644 --- a/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/fi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS provides a wide range of useful tools for monitoring queries: - [Traffic destination](/private-dns/statistics-and-log/traffic-destination.md) - [Companies](/private-dns/statistics-and-log/companies.md) - [Query log](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/fr/code.json b/i18n/fr/code.json index 3358d8234..389259557 100644 --- a/i18n/fr/code.json +++ b/i18n/fr/code.json @@ -8,11 +8,11 @@ "description": "The site tagline used in meta description" }, "apiChangelog.loading": { - "message": "Loading changelog…", + "message": "Chargement du journal des modifications…", "description": "Placeholder shown while the API changelog is being loaded" }, "apiChangelog.error": { - "message": "Failed to load the changelog. You can view the original at {link}.", + "message": "Échec du chargement du journal des modifications. Vous pouvez voir l'original à l'adresse {link}.", "description": "Error message shown when the API changelog cannot be loaded. {link} is a link to the original changelog on adguard-dns.io" }, "apiChangelog.versions": { @@ -20,7 +20,7 @@ "description": "Accessible name of the version list sidebar on the API changelog page" }, "apiReference.loading": { - "message": "Loading API reference…", + "message": "Chargement de la référence de l'API…", "description": "Placeholder shown while the API reference (Swagger UI) is being loaded" }, "theme.NotFound.title": { @@ -72,127 +72,127 @@ "description": "The blog post button label to navigate to the newer/previous post" }, "theme.blog.post.paginator.olderPost": { - "message": "Older Post", + "message": "Billet plus ancien", "description": "The blog post button label to navigate to the older/next post" }, "theme.blog.sidebar.navAriaLabel": { - "message": "Recent blog posts navigation", + "message": "Navigation dans les billets récents du blogue", "description": "The ARIA label for recent posts in the blog sidebar" }, "theme.tags.tagsPageTitle": { - "message": "Tags", + "message": "Étiquettes", "description": "The title of the tag list page" }, "theme.blog.post.plurals": { - "message": "One post|{count} posts", + "message": "Un billet|{count} billets", "description": "Pluralized label for \"{count} posts\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.blog.tagTitle": { - "message": "{nPosts} tagged with \"{tagName}\"", + "message": "{nPosts} étiqueté(s) avec \"{tagName}\"", "description": "The title of the page for a blog tag" }, "theme.tags.tagsPageLink": { - "message": "View All Tags", + "message": "Afficher toutes les étiquettes", "description": "The label of the link targeting the tag list page" }, "theme.CodeBlock.copyButtonAriaLabel": { - "message": "Copy code to clipboard", + "message": "Copier le code dans le presse-papiers", "description": "The ARIA label for copy code blocks button" }, "theme.CodeBlock.copied": { - "message": "Copied", + "message": "Copié", "description": "The copied button label on code blocks" }, "theme.CodeBlock.copy": { - "message": "Copy", + "message": "Copier", "description": "The copy button label on code blocks" }, "theme.docs.sidebar.expandButtonTitle": { - "message": "Expand sidebar", + "message": "Développer la barre latérale", "description": "The ARIA label and title attribute for expand button of doc sidebar" }, "theme.docs.sidebar.expandButtonAriaLabel": { - "message": "Expand sidebar", + "message": "Développer la barre latérale", "description": "The ARIA label and title attribute for expand button of doc sidebar" }, "theme.docs.paginator.navAriaLabel": { - "message": "Docs pages navigation", + "message": "Navigation dans les pages des documents", "description": "The ARIA label for the docs pagination" }, "theme.docs.paginator.previous": { - "message": "Previous", + "message": "Précédent", "description": "The label used to navigate to the previous doc" }, "theme.docs.paginator.next": { - "message": "Next", + "message": "Suivant", "description": "The label used to navigate to the next doc" }, "theme.docs.sidebar.collapseButtonTitle": { - "message": "Collapse sidebar", + "message": "Réduire la barre latérale", "description": "The title attribute for collapse button of doc sidebar" }, "theme.docs.sidebar.collapseButtonAriaLabel": { - "message": "Collapse sidebar", + "message": "Réduire la barre latérale", "description": "The title attribute for collapse button of doc sidebar" }, "theme.docs.versions.unreleasedVersionLabel": { - "message": "This is unreleased documentation for {siteTitle} {versionLabel} version.", + "message": "Ceci est une documentation non publiée pour la version {versionLabel} de {siteTitle}.", "description": "The label used to tell the user that he's browsing an unreleased doc version" }, "theme.docs.versions.unmaintainedVersionLabel": { - "message": "This is documentation for {siteTitle} {versionLabel}, which is no longer actively maintained.", + "message": "Ceci est une documentation pour la version {versionLabel} de {siteTitle}, qui n'est plus activement maintenue.", "description": "The label used to tell the user that he's browsing an unmaintained doc version" }, "theme.docs.versions.latestVersionSuggestionLabel": { - "message": "For up-to-date documentation, see the {latestVersionLink} ({versionLabel}).", + "message": "Pour la documentation à jour, consultez {latestVersionLink} ({versionLabel}).", "description": "The label used to tell the user to check the latest version" }, "theme.docs.versions.latestVersionLinkLabel": { - "message": "latest version", + "message": "version la plus récente", "description": "The label used for the latest version suggestion link label" }, "theme.common.editThisPage": { - "message": "Edit this page", + "message": "Modifier cette page", "description": "The link label to edit the current page" }, "theme.common.headingLinkTitle": { - "message": "Direct link to heading", + "message": "Lien direct vers le titre", "description": "Title for link to heading" }, "theme.lastUpdated.atDate": { - "message": " on {date}", + "message": " le {date}", "description": "The words used to describe on which date a page has been last updated" }, "theme.lastUpdated.byUser": { - "message": " by {user}", + "message": " par {user}", "description": "The words used to describe by who the page has been last updated" }, "theme.lastUpdated.lastUpdatedAtBy": { - "message": "Last updated{atDate}{byUser}", + "message": "Dernière mise à jour {atDate} {byUser}", "description": "The sentence used to display when a page has been last updated, and by who" }, "theme.navbar.mobileSidebarSecondaryMenu.backButtonLabel": { - "message": "← Back to main menu", + "message": "← Retour au menu principal", "description": "The label of the back button to return to main menu, inside the mobile navbar sidebar secondary menu (notably used to display the docs sidebar)" }, "theme.common.skipToMainContent": { - "message": "Skip to main content", + "message": "Aller au contenu principal", "description": "The skip to content label used for accessibility, allowing to rapidly navigate to main content with keyboard tab/enter navigation" }, "theme.TOCCollapsible.toggleButtonLabel": { - "message": "On this page", + "message": "Sur cette page", "description": "The label used by the button on the collapsible TOC component" }, "theme.ErrorPageContent.title": { - "message": "This page crashed.", + "message": "Cette page a planté.", "description": "The title of the fallback page when the page crashed" }, "theme.ErrorPageContent.tryAgain": { - "message": "Try again", + "message": "Réessayer", "description": "The label of the button to try again rendering when the React error boundary captures an error" }, "theme.BackToTopButton.buttonAriaLabel": { - "message": "Scroll back to top", + "message": "Défiler au haut de la page", "description": "The ARIA label for the back to top button" }, "theme.blog.archive.title": { @@ -204,120 +204,120 @@ "description": "The page & hero description of the blog archive page" }, "theme.blog.post.readMoreLabel": { - "message": "Read more about {title}", + "message": "En savoir plus sur {title}", "description": "The ARIA label for the link to full blog posts from excerpts" }, "theme.colorToggle.ariaLabel": { - "message": "Switch between dark and light mode (currently {mode})", + "message": "Basculer entre les modes sombre et clair (actuellement {mode})", "description": "The ARIA label for the color mode toggle" }, "theme.colorToggle.ariaLabel.mode.dark": { - "message": "dark mode", + "message": "mode sombre", "description": "The name for the dark color mode" }, "theme.colorToggle.ariaLabel.mode.light": { - "message": "light mode", + "message": "mode clair", "description": "The name for the light color mode" }, "theme.docs.breadcrumbs.home": { - "message": "Home page", + "message": "Page d'accueil", "description": "The ARIA label for the home page in the breadcrumbs" }, "theme.docs.breadcrumbs.navAriaLabel": { - "message": "Breadcrumbs", + "message": "Fil d’Ariane", "description": "The ARIA label for the breadcrumbs" }, "theme.docs.DocCard.categoryDescription": { - "message": "{count} items", + "message": "{count} éléments", "description": "The default description for a category card in the generated index about how many items this category includes" }, "theme.docs.tagDocListPageTitle.nDocsTagged": { - "message": "One doc tagged|{count} docs tagged", + "message": "Un document étiqueté|{count} documents étiquetés", "description": "Pluralized label for \"{count} docs tagged\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.docs.tagDocListPageTitle": { - "message": "{nDocsTagged} with \"{tagName}\"", + "message": "{nDocsTagged} avec « {tagName} »", "description": "The title of the page for a docs tag" }, "theme.docs.versionBadge.label": { - "message": "Version: {versionLabel}" + "message": "Version : {versionLabel}" }, "theme.navbar.mobileVersionsDropdown.label": { "message": "Versions", "description": "The label for the navbar versions dropdown on mobile view" }, "theme.CodeBlock.wordWrapToggle": { - "message": "Toggle word wrap", + "message": "Basculer le retour à la ligne", "description": "The title attribute for toggle word wrapping button of code block lines" }, "theme.DocSidebarItem.toggleCollapsedCategoryAriaLabel": { - "message": "Toggle the collapsible sidebar category '{label}'", + "message": "Basculer la catégorie de la barre latérale réductible '{label}'", "description": "The ARIA label to toggle the collapsible sidebar category" }, "theme.navbar.mobileLanguageDropdown.label": { - "message": "Languages", + "message": "Langues", "description": "The label for the mobile language switcher dropdown" }, "theme.IdealImageMessage.loading": { - "message": "Loading...", + "message": "Chargement en cours...", "description": "When the full-scale image is loading" }, "theme.IdealImageMessage.load": { - "message": "Click to load{sizeMessage}", + "message": "Cliquez pour charger {sizeMessage}", "description": "To prompt users to load the full image. sizeMessage is a parenthesized size figure." }, "theme.IdealImageMessage.offline": { - "message": "Your browser is offline. Image not loaded", + "message": "Votre navigateur est hors ligne. Image non chargée", "description": "When the user is viewing an offline document" }, "theme.IdealImageMessage.404error": { - "message": "404. Image not found", + "message": "404. Image non trouvée", "description": "When the image is not found" }, "theme.IdealImageMessage.error": { - "message": "Error. Click to reload", + "message": "Erreur. Cliquez pour recharger", "description": "When the image fails to load for unknown error" }, "theme.SearchBar.noResultsText": { - "message": "No results" + "message": "Pas de résultats" }, "theme.SearchBar.seeAll": { - "message": "See all results" + "message": "Voir tous les résultats" }, "theme.SearchBar.label": { - "message": "Search", + "message": "Chercher", "description": "The ARIA label and placeholder for search button" }, "theme.SearchPage.existingResultsTitle": { - "message": "Search results for \"{query}\"", + "message": "Résultats de la recherche pour \"{query}\"", "description": "The search page title for non-empty query" }, "theme.SearchPage.emptyResultsTitle": { - "message": "Search the documentation", + "message": "Rechercher dans la documentation", "description": "The search page title for empty query" }, "theme.SearchPage.documentsFound.plurals": { - "message": "One document found|{count} documents found", + "message": "Un document trouvé|{count} documents trouvés", "description": "Pluralized label for \"{count} documents found\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.SearchPage.noResultsText": { - "message": "No documents were found", + "message": "Aucuns documents n'ont été trouvés", "description": "The paragraph for empty search result" }, "theme.SearchPage.inputPlaceholder": { - "message": "Type your search here", + "message": "Saisissez votre recherche ici", "description": "The placeholder for search page input" }, "theme.SearchPage.inputLabel": { - "message": "Search", + "message": "Chercher", "description": "The ARIA label for search page input" }, "theme.SearchPage.algoliaLabel": { - "message": "Search by Typesense", + "message": "Rechercher avec Typesense", "description": "The ARIA label for Typesense mention" }, "theme.SearchPage.fetchingNewResults": { - "message": "Fetching new results...", + "message": "Récupération de nouveaux résultats...", "description": "The paragraph for fetching new search results" }, "theme.admonition.note": { @@ -325,7 +325,7 @@ "description": "The default label used for the Note admonition (:::note)" }, "theme.admonition.tip": { - "message": "tip", + "message": "conseil", "description": "The default label used for the Tip admonition (:::tip)" }, "theme.admonition.danger": { @@ -337,147 +337,147 @@ "description": "The default label used for the Info admonition (:::info)" }, "theme.admonition.caution": { - "message": "caution", + "message": "prudence", "description": "The default label used for the Caution admonition (:::caution)" }, "theme.NavBar.navAriaLabel": { - "message": "Main", + "message": "Principal", "description": "The ARIA label for the main navigation" }, "theme.docs.sidebar.navAriaLabel": { - "message": "Docs sidebar", + "message": "Barre latérale des documents", "description": "The ARIA label for the sidebar navigation" }, "theme.docs.sidebar.closeSidebarButtonAriaLabel": { - "message": "Close navigation bar", + "message": "Fermer la barre de navigation", "description": "The ARIA label for close button of mobile sidebar" }, "theme.docs.sidebar.toggleSidebarButtonAriaLabel": { - "message": "Toggle navigation bar", + "message": "Basculer la barre de navigation", "description": "The ARIA label for hamburger menu button of mobile navigation" }, "theme.SearchPage.typesenseLabel": { - "message": "Search by Typesense", + "message": "Rechercher avec Typesense", "description": "The ARIA label for Typesense mention" }, "theme.SearchModal.searchBox.resetButtonTitle": { - "message": "Clear the query", + "message": "Effacer la requête", "description": "The label and ARIA label for search box reset button" }, "theme.SearchModal.searchBox.cancelButtonText": { - "message": "Cancel", + "message": "Annuler", "description": "The label and ARIA label for search box cancel button" }, "theme.SearchModal.startScreen.recentSearchesTitle": { - "message": "Recent", + "message": "Récent", "description": "The title for recent searches" }, "theme.SearchModal.startScreen.noRecentSearchesText": { - "message": "No recent searches", + "message": "Aucune recherche récente", "description": "The text when no recent searches" }, "theme.SearchModal.startScreen.saveRecentSearchButtonTitle": { - "message": "Save this search", + "message": "Enregistrer cette recherche", "description": "The label for save recent search button" }, "theme.SearchModal.startScreen.removeRecentSearchButtonTitle": { - "message": "Remove this search from history", + "message": "Retirer cette recherche de l'historique", "description": "The label for remove recent search button" }, "theme.SearchModal.startScreen.favoriteSearchesTitle": { - "message": "Favorite", + "message": "Favoris", "description": "The title for favorite searches" }, "theme.SearchModal.startScreen.removeFavoriteSearchButtonTitle": { - "message": "Remove this search from favorites", + "message": "Retirer cette recherche des favoris", "description": "The label for remove favorite search button" }, "theme.SearchModal.errorScreen.titleText": { - "message": "Unable to fetch results", + "message": "Impossible de récupérer les résultats", "description": "The title for error screen of search modal" }, "theme.SearchModal.errorScreen.helpText": { - "message": "You might want to check your network connection.", + "message": "Vous voudrez peut-être vérifier votre connexion réseau.", "description": "The help text for error screen of search modal" }, "theme.SearchModal.footer.selectText": { - "message": "to select", + "message": "pour sélectionner", "description": "The explanatory text of the action for the enter key" }, "theme.SearchModal.footer.selectKeyAriaLabel": { - "message": "Enter key", + "message": "Touche Entrée", "description": "The ARIA label for the Enter key button that makes the selection" }, "theme.SearchModal.footer.navigateText": { - "message": "to navigate", + "message": "pour naviguer", "description": "The explanatory text of the action for the Arrow up and Arrow down key" }, "theme.SearchModal.footer.navigateUpKeyAriaLabel": { - "message": "Arrow up", + "message": "Flèche haut", "description": "The ARIA label for the Arrow up key button that makes the navigation" }, "theme.SearchModal.footer.navigateDownKeyAriaLabel": { - "message": "Arrow down", + "message": "Flèche bas", "description": "The ARIA label for the Arrow down key button that makes the navigation" }, "theme.SearchModal.footer.closeText": { - "message": "to close", + "message": "pour fermer", "description": "The explanatory text of the action for Escape key" }, "theme.SearchModal.footer.closeKeyAriaLabel": { - "message": "Escape key", + "message": "Touche Échap", "description": "The ARIA label for the Escape key button that close the modal" }, "theme.SearchModal.footer.searchByText": { - "message": "Search by", + "message": "Recherche par", "description": "The text explain that the search is making by Algolia" }, "theme.SearchModal.noResultsScreen.noResultsText": { - "message": "No results for", + "message": "Aucun résultat pour", "description": "The text explains that there are no results for the following search" }, "theme.SearchModal.noResultsScreen.suggestedQueryText": { - "message": "Try searching for", + "message": "Essayez de rechercher", "description": "The text for the suggested query when no results are found for the following search" }, "theme.SearchModal.noResultsScreen.reportMissingResultsText": { - "message": "Believe this query should return results?", + "message": "Vous pensez que cette requête devrait renvoyer des résultats ?", "description": "The text for the question where the user thinks there are missing results" }, "theme.SearchModal.noResultsScreen.reportMissingResultsLinkText": { - "message": "Let us know.", + "message": "Faites-le nous savoir.", "description": "The text for the link to report missing results" }, "theme.SearchModal.placeholder": { - "message": "Search docs", + "message": "Rechercher dans les documents", "description": "The placeholder of the input of the DocSearch pop-up modal" }, "theme.colorToggle.ariaLabel.mode.system": { - "message": "system mode", + "message": "mode système", "description": "The name for the system color mode" }, "theme.admonition.warning": { - "message": "warning", + "message": "avertissement", "description": "The default label used for the Warning admonition (:::warning)" }, "theme.DocSidebarItem.expandCategoryAriaLabel": { - "message": "Expand sidebar category '{label}'", + "message": "Développer la catégorie de la barre latérale «{label}»", "description": "The ARIA label to expand the sidebar category" }, "theme.DocSidebarItem.collapseCategoryAriaLabel": { - "message": "Collapse sidebar category '{label}'", + "message": "Réduire la catégorie de la barre latérale «{label}»", "description": "The ARIA label to collapse the sidebar category" }, "theme.IconExternalLink.ariaLabel": { - "message": "(opens in new tab)", + "message": "(s’ouvre dans un nouvel onglet)", "description": "The ARIA label for the external link icon" }, "theme.navbar.mobileDropdown.collapseButton.expandAriaLabel": { - "message": "Expand the dropdown", + "message": "Agrandir le menu déroulant", "description": "The ARIA label of the button to expand the mobile dropdown navbar item" }, "theme.navbar.mobileDropdown.collapseButton.collapseAriaLabel": { - "message": "Collapse the dropdown", + "message": "Réduire le menu déroulant", "description": "The ARIA label of the button to collapse the mobile dropdown navbar item" }, "theme.blog.author.pageTitle": { @@ -485,35 +485,35 @@ "description": "The title of the page for a blog author" }, "theme.blog.authorsList.pageTitle": { - "message": "Authors", + "message": "Auteurs", "description": "The title of the authors page" }, "theme.blog.authorsList.viewAll": { - "message": "View all authors", + "message": "Voir tous les auteurs", "description": "The label of the link targeting the blog authors page" }, "theme.blog.author.noPosts": { - "message": "This author has not written any posts yet.", + "message": "Cet auteur n'a pas encore écrit d'articles.", "description": "The text for authors with 0 blog post" }, "theme.contentVisibility.unlistedBanner.title": { - "message": "Unlisted page", + "message": "Page non répertoriée", "description": "The unlisted content banner title" }, "theme.contentVisibility.unlistedBanner.message": { - "message": "This page is unlisted. Search engines will not index it, and only users having a direct link can access it.", + "message": "Cette page n'est pas répertoriée. Les moteurs de recherche ne l'indexeront pas, et seuls les utilisateurs disposant d'un lien direct peuvent y accéder.", "description": "The unlisted content banner message" }, "theme.contentVisibility.draftBanner.title": { - "message": "Draft page", + "message": "Page brouillon", "description": "The draft content banner title" }, "theme.contentVisibility.draftBanner.message": { - "message": "This page is a draft. It will only be visible in dev and be excluded from the production build.", + "message": "Cette page est un brouillon. Elle ne sera visible que dans l'environnement de développement et ne sera pas incluse dans la version de production.", "description": "The draft content banner message" }, "theme.docs.DocCard.categoryDescription.plurals": { - "message": "1 item|{count} items", + "message": "1 élément |{count} éléments", "description": "The default description for a category card in the generated index about how many items this category includes" } } diff --git a/i18n/fr/docusaurus-plugin-content-docs/current.json b/i18n/fr/docusaurus-plugin-content-docs/current.json index 652dd53ab..97fd372d0 100644 --- a/i18n/fr/docusaurus-plugin-content-docs/current.json +++ b/i18n/fr/docusaurus-plugin-content-docs/current.json @@ -1,6 +1,6 @@ { "version.label": { - "message": "Next", + "message": "Suivant", "description": "The label for version current" }, "sidebar.sidebar.category.General": { diff --git a/i18n/fr/docusaurus-plugin-content-docs/current/adguard-home/faq.md b/i18n/fr/docusaurus-plugin-content-docs/current/adguard-home/faq.md index 5683dd6e2..64182ba89 100644 --- a/i18n/fr/docusaurus-plugin-content-docs/current/adguard-home/faq.md +++ b/i18n/fr/docusaurus-plugin-content-docs/current/adguard-home/faq.md @@ -165,11 +165,11 @@ Il n'existe actuellement aucun moyen de définir ces paramètres depuis l'interf 2. Ouvrez `AdGuardHome.yaml` dans votre éditeur. -3. Set the `http.address` setting to a new network interface. Par exemple : +3. Définissez le paramètre `http.address` sur une nouvelle interface réseau. Par exemple : - - `0.0.0.0:0` to listen on all network interfaces; - - `0.0.0.0:8080` to listen on all network interfaces with port `8080`; - - `127.0.0.1:0` to listen on the local loopback interface only. + - `0.0.0.0:0` pour écouter sur toutes les interfaces réseau ; + - `0.0.0.0:8080` pour écouter sur toutes les interfaces réseau avec le port `8080` ; + - `127.0.0.1:0` pour écouter uniquement sur l'interface de boucle locale. 4. Redémarrez AdGuard Home : @@ -177,35 +177,35 @@ Il n'existe actuellement aucun moyen de définir ces paramètres depuis l'interf ./AdGuardHome -s start ``` -## How do I set up AdGuard Home as default DNS server? {#defaultdns} +## Comment configurer AdGuard Home en tant que serveur DNS par défaut ? {#defaultdns} -See the [_Configuring Devices_ section](/adguard-home/getting-started#configure-devices) on the _Getting Started_ page. +Consultez la section [_Configuration des appareils_](/adguard-home/getting-started#configure-devices) sur la page _Premiers pas_. -## Are there any known limitations? {#limitations} +## Existe-t-il des limitations connues ? {#limitations} -Here are some examples of what cannot be blocked by a DNS-level blocker: +Voici quelques exemples de ce qui ne peut pas être bloqué par un bloqueur au niveau DNS : -- YouTube, Twitch ads. +- YouTube, publicités Twitch. -- Facebook, X (formerly Twitter), Instagram sponsored posts. +- Facebook, X (anciennement Twitter), publications sponsorisées Instagram. -Basically, any ad that shares a domain with content cannot be blocked by a DNS-level blocker, unless you are ready to block the content as well. +Fondamentalement, toute publicité qui partage un domaine de contenu ne peut pas être bloquée par un bloqueur au niveau DNS, à moins que vous ne soyez prêt à bloquer le contenu également. -### Any possibility of dealing with this in the future? +### Y a-t-il une possibilité de résoudre cela à l'avenir ? -DNS will never be enough to do this. Your only option is to use a content blocking proxy like what we do in the [standalone AdGuard applications][adguard]. We’ll be adding support for this feature to AdGuard Home in the future. Unfortunately, even then there will still be cases where it won’t be enough or it will require quite complicated configuration. +DNS ne sera jamais suffisant pour cela. Votre seule option est d'utiliser un proxy de blocage de contenu comme ce que nous faisons dans les [applications AdGuard autonomes][adguard]. Nous ajouterons la prise en charge de cette fonctionnalité à AdGuard Home à l'avenir. Malheureusement, même alors, il y aura encore des cas où cela ne sera pas suffisant ou nécessitera une configuration assez compliquée. [adguard]: https://adguard.com/ -## Why do I get `bind: address already in use` error when trying to install on Ubuntu? {#bindinuse} +## Pourquoi obtiens-je l'erreur `bind: address already in use` lorsque j'essaie d'installer sur Ubuntu ? {#bindinuse} -This happens because the port 53 on `localhost`, which is used for DNS, is already taken by another program. Ubuntu comes with a local DNS called `systemd-resolved`, which uses the address `127.0.0.53:53`, thus preventing AdGuard Home from binding to `127.0.0.1:53`. You can see this by running: +Cela se produit parce que le port 53 sur `localhost`, qui est utilisé pour DNS, est déjà pris par un autre programme. Ubuntu est livré avec un DNS local appelé `systemd-resolved`, qui utilise l'adresse `127.0.0.53:53`, empêchant donc AdGuard Home de se lier à `127.0.0.1:53`. Vous pouvez voir cela en exécutant : ```sh sudo lsof -i :53 ``` -The output should be similar to: +La sortie devrait être semblable à : ```none COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME @@ -213,9 +213,9 @@ systemd-r 14542 systemd-resolve 13u IPv4 86178 0t0 UDP 127.0.0.53:domain systemd-r 14542 systemd-resolve 14u IPv4 86179 0t0 TCP 127.0.0.53:domain ``` -To fix this, you must either disable the `systemd-resolved` daemon or choose a different network interface and bind your AdGuard Home to an accessible IP address on it, such as the IP address of your router inside your network. But if you do need to listen on `localhost`, there are several solutions. +Pour résoudre cela, vous devez soit désactiver le démon `systemd-resolved`, soit choisir une autre interface réseau et lier votre AdGuard Home à une adresse IP accessible dessus, telle que l'adresse IP de votre routeur dans votre réseau. Mais si vous devez écouter sur `localhost`, il existe plusieurs solutions. -Firstly, AdGuard Home can detect such configurations and disable `systemd-resolved` for you if you press the _Fix_ button located next to the `address already in use` message on the installation screen. +Tout d'abord, AdGuard Home peut détecter de telles configurations et désactiver `systemd-resolved` pour vous si vous appuyez sur le bouton _Réparer_ situé à côté du message `address already in use` sur l'écran d'installation. Secondly, if that doesn’t work, follow the instructions below. Note that if you’re using AdGuard Home with docker or snap, you’ll have to do this yourself. diff --git a/i18n/fr/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/fr/docusaurus-plugin-content-docs/current/general/dns-providers.md index 5b13f25b2..4ea8b690a 100644 --- a/i18n/fr/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/fr/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### Sans filtrage - -| Protocole | Adresse | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| Protocole | Adresse | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Ad + malware blocking - -| Protocole | Adresse | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Ad + malware + social media blocking - -| Protocole | Adresse | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Ad + malware + adult + gambling blocking - -| Protocole | Adresse | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Ad + malware + adult + gambling + social media blocking - -| Protocole | Adresse | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### Unsecured -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protocole | Adresse | | | -------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md b/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md index 1942354a7..97aeaa508 100644 --- a/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md +++ b/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md @@ -9,7 +9,7 @@ DNS-over-HTTPS avec authentification vous permet de définir un nom d'utilisateu Cela aide à prévenir les utilisateurs non autorisés d'y accéder et améliore la sécurité. De plus, vous pouvez restreindre l'utilisation d'autres protocoles pour des profils spécifiques. Cette fonctionnalité est particulièrement utile lorsque l'adresse de votre serveur DNS est connue d'autres personnes. En ajoutant un mot de passe, vous pouvez bloquer l'accès et vous assurer que vous seul pouvez l'utiliser. -## Comment le mettre en place +## How to set it up :::note Compatibilité diff --git a/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md b/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md index c93e9f5f8..ebab1133b 100644 --- a/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md +++ b/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md @@ -7,7 +7,7 @@ En configurant les paramètres d'accès, vous pouvez protéger votre AdGuard DNS Les requêtes bloquées ne seront pas affichées dans le Journal des requêtes et ne sont pas comptées dans la limite totale. -## Comment le mettre en place +## How to set it up ### Clients autorisés diff --git a/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index 9d177025b..6a0275a34 100644 --- a/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,48 +3,58 @@ title: Contrôle Parental sidebar_position: 5 --- -## Qu'est-ce que c'est +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. -Le contrôle parental est un ensemble de paramètres qui vous donne la flexibilité de personnaliser l'accès à certains sites Web avec un contenu "sensible". Vous pouvez utiliser cette fonctionnalité pour restreindre l'accès de vos enfants aux sites pour adultes, personnaliser les requêtes de recherche, bloquer l'utilisation de services populaires, et plus encore. +## How to set it up -## Comment le mettre en place +You can flexibly configure all features on your servers, including the parental control feature. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. -Vous pouvez configurer de manière flexible toutes les fonctionnalités sur vos serveurs, y compris la fonctionnalité de contrôle parental. [Dans l'article correspondant](private-dns/server-and-settings/server-and-settings.md), vous pouvez vous familiariser avec ce qu'est un "serveur" dans AdGuard DNS et apprendre à créer différents serveurs avec différents ensembles de paramètres. +Then, go to the settings of the selected server and enable the required configurations. -Ensuite, accédez aux paramètres du serveur sélectionné et activez les configurations requises. +### Block adult websites -### Bloquer les sites à contenu adulte +Blocks websites with inappropriate and adult content. -Bloque les sites Web ayant des contenus inappropriés et pour adultes. +![Blocked website \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) -![Site Web bloqué \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) +### Safe search -### Recherche sécurisée +Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -Supprime les résultats inappropriés de Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, et Ecosia. +### YouTube restricted mode -![Recherche sécurisée \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) +Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -### Mode limité YouTube +### Blocked services and websites -Supprime l'option de visionner et de publier des commentaires sous les vidéos et d'interagir avec du contenu 18+ sur YouTube. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. -![Mode restreint \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) +![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) -### Services et sites Web bloqués +### Block websites by category -AdGuard DNS bloque l'accès aux services populaires en un clic. C'est utile si vous ne voulez pas que les appareils connectés visitent Instagram et YouTube, par exemple. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. -![Services bloqués \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) -### Bloquez les sites Web par catégorie +### Pause schedule -Cette fonction vous permet de restreindre l'accès à des catégories spécifiques de sites web en choisissant parmi plus de 20 catégories, dont _Contenu pour adultes_, _Jeux_, _Services bancaires_ et _Communication_. Par exemple, si vous bloquez les sites contenant des informations sur l'alcool, le tabac ou les drogues, l'appareil sélectionné ne pourra plus ouvrir les pages appartenant à ces catégories. +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. -![Blocage basé sur les catégories \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. -### L'horaire est décalé +To set up a pause schedule: -Active les contrôles parentaux les jours sélectionnés avec un intervalle de temps spécifié. Par exemple, vous pouvez avoir autorisé votre enfant à regarder des vidéos YouTube seulement jusqu'à 23h00 en semaine. Mais le week-end, cet accès n'est pas restreint. Personnalisez l'horaire à votre goût et bloquez l'accès à des sites sélectionnés pendant les heures que vous souhaitez. +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. -![Horaire \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. + +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) + +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. + +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. + +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index c926484d0..f0c37a78b 100644 --- a/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ Celles-ci sont divisées en sous-catégories : - **CDN** : requête liée au réseau de diffusion de contenu (CDN), un réseau mondial de serveurs proxy qui accélère la diffusion de contenu aux utilisateurs finaux - **Autre** -### Top des sociétés +## Top des sociétés Dans ce tableau, nous ne montrons pas seulement les noms des sociétés les plus visitées ou les plus bloquées, mais nous affichons également des informations sur les domaines qui sont demandés ou qui sont les plus souvent bloqués. diff --git a/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..85b0c2c41 --- /dev/null +++ b/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Obligatoire | Description | Example | +| :---------------- | :------------ | :---------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | Non | Detected account ID, if any. | `1234` | +| `DnsServerId` | chaîne | Non | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | chaîne | Non | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | chaîne | Non | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | chaîne | Non | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | chaîne | Oui | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | chaîne | Non | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | chaîne | Non | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Oui | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | Non | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Oui | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Oui | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Oui | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Oui | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Oui | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Oui | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Oui | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | chaîne | Non | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Oui | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Oui | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## FAQ + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 91db2281b..9fc4a5ec1 100644 --- a/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Journal des requêtes sidebar_position: 5 --- -## Qu'est-ce que le journal des requêtes +## What is Query log? -Le journal des requêtes est un outil utile pour travailler avec AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. Il vous permet de voir toutes les requêtes effectuées par vos appareils pendant la période sélectionnée et de trier les requêtes par état, type, sosiété, appareil, pays. ## Comment l'utiliser -Voici ce que vous pouvez voir et ce que vous pouvez faire dans le _Journal des requêtes_. +Here’s what you can see and what you can do in _Query log_. ### Informations détaillées sur les requêtes -![Informations sur les requêtes \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Blocage et déblocage des domaines Les requêtes peuvent être bloquées et débloquées sans quitter le journal, en utilisant les outils disponibles. -![Débloquer un domaine \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Tri des requêtes diff --git a/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index 73e088920..c929e735d 100644 --- a/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/fr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS fournit une large plage d'outils utiles pour surveiller les requête - [Destination du trafic](/private-dns/statistics-and-log/traffic-destination.md) - [Sociétés](/private-dns/statistics-and-log/companies.md) - [Journal des requêtes](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/hr/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/hr/docusaurus-plugin-content-docs/current/general/dns-providers.md index 614bfba98..15348bd48 100644 --- a/i18n/hr/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/hr/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### Non-filtering - -| Protocol | Address | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| Protocol | Address | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Ad + malware blocking - -| Protocol | Address | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Ad + malware + social media blocking - -| Protocol | Address | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Ad + malware + adult + gambling blocking - -| Protocol | Address | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Ad + malware + adult + gambling + social media blocking - -| Protocol | Address | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### Unsecured -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protocol | Address | | | -------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index cd2a4ad76..143c85ffa 100644 --- a/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,9 +3,7 @@ title: Parental control sidebar_position: 5 --- -## What is it - -Parental control is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. ## How to set it up @@ -23,28 +21,40 @@ Blocks websites with inappropriate and adult content. Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -![Safe search \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) - ### YouTube restricted mode Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -![Restricted mode \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) - ### Blocked services and websites -AdGuard DNS blocks access to popular services with one click. It’s useful if you don’t want connected devices to visit Instagram and YouTube, for example. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. ![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) ### Block websites by category -This feature lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. + +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) + +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. + +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### Schedule off time +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -Enables parental controls on selected days with a specified time interval. For example, you may have allowed your child to watch YouTube videos only until 23:00 on weekdays. But on weekends, this access is not restricted. Customize the schedule to your liking and block access to selected sites during the hours you want. +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![Schedule \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index b21375a03..1e626b858 100644 --- a/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ These are further divided into sub-categories: - **CDN**: request connected to Content Delivery Network (CDN), a worldwide network of proxy servers that speeds the delivery of content to end users - **Other** -### Top companies +## Top companies In this table, we not only show the names of the most visited or most blocked companies, but also display information about which domains are being requested from or which domains are being blocked the most. diff --git a/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..aee6e9122 --- /dev/null +++ b/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Required | Description | Example | +| :---------------- | :------------ | :------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | No | Detected account ID, if any. | `1234` | +| `DnsServerId` | string | No | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | string | No | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | string | No | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | string | No | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | string | Yes | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | string | No | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | string | No | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Yes | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | No | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Yes | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Yes | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Yes | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Yes | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Yes | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Yes | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Yes | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | string | No | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Yes | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Yes | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## Česta pitanja + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 90ecc6874..3367affbe 100644 --- a/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Query log sidebar_position: 5 --- -## What is Query log +## What is Query log? -Query log is a useful tool for working with AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. It allows you to view all requests made by your devices during the selected time period and sort requests by status, type, company, device, country. ## How to use it -Here’s what you can see and what you can do in the _Query log_. +Here’s what you can see and what you can do in _Query log_. ### Detailed information on requests -![Requests info \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Blocking and unblocking domains Requests can be blocked and unblocked without leaving the log, using the available tools. -![Unblock domain \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Sorting requests diff --git a/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index b9047787e..4281c19bb 100644 --- a/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/hr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS provides a wide range of useful tools for monitoring queries: - [Traffic destination](/private-dns/statistics-and-log/traffic-destination.md) - [Companies](/private-dns/statistics-and-log/companies.md) - [Query log](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/it/code.json b/i18n/it/code.json index 42f4ba161..6b640eaba 100644 --- a/i18n/it/code.json +++ b/i18n/it/code.json @@ -8,51 +8,51 @@ "description": "The site tagline used in meta description" }, "apiChangelog.loading": { - "message": "Loading changelog…", + "message": "Caricamento del registro delle modifiche…", "description": "Placeholder shown while the API changelog is being loaded" }, "apiChangelog.error": { - "message": "Failed to load the changelog. You can view the original at {link}.", + "message": "Impossibile caricare il registro delle modifiche. Puoi visualizzare l'originale all'indirizzo {link}.", "description": "Error message shown when the API changelog cannot be loaded. {link} is a link to the original changelog on adguard-dns.io" }, "apiChangelog.versions": { - "message": "Versions", + "message": "Versioni", "description": "Accessible name of the version list sidebar on the API changelog page" }, "apiReference.loading": { - "message": "Loading API reference…", + "message": "Caricamento del riferimento API…", "description": "Placeholder shown while the API reference (Swagger UI) is being loaded" }, "theme.NotFound.title": { - "message": "Page Not Found", + "message": "Pagina non trovata", "description": "The title of the 404 page" }, "theme.NotFound.p1": { - "message": "We could not find what you were looking for.", + "message": "Non siamo riusciti a trovare quello che stavi cercando.", "description": "The first paragraph of the 404 page" }, "theme.NotFound.p2": { - "message": "Please contact the owner of the site that linked you to the original URL and let them know their link is broken.", + "message": "Per favore contattare il proprietario del sito che vi ha collegato all'URL originale e informatelo che il suo link è interrotto.", "description": "The 2nd paragraph of the 404 page" }, "theme.AnnouncementBar.closeButtonAriaLabel": { - "message": "Close", + "message": "Chiudi", "description": "The ARIA label for close button of announcement bar" }, "theme.blog.paginator.navAriaLabel": { - "message": "Blog list page navigation", + "message": "Navigazione nella pagina dell'elenco di blog", "description": "The ARIA label for the blog pagination" }, "theme.blog.paginator.newerEntries": { - "message": "Newer Entries", + "message": "Voci più recenti", "description": "The label used to navigate to the newer blog posts page (previous page)" }, "theme.blog.paginator.olderEntries": { - "message": "Older Entries", + "message": "Voci meno recenti", "description": "The label used to navigate to the older blog posts page (next page)" }, "theme.blog.post.readingTime.plurals": { - "message": "One min read|{readingTime} min read", + "message": "Lettura di un minuto|{readingTime} minuti di lettura", "description": "Pluralized label for \"{readingTime} min read\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.tags.tagsListLabel": { @@ -60,264 +60,264 @@ "description": "The label alongside a tag list" }, "theme.blog.post.readMore": { - "message": "Read More", + "message": "Altro", "description": "The label used in blog post item excerpts to link to full blog posts" }, "theme.blog.post.paginator.navAriaLabel": { - "message": "Blog post page navigation", + "message": "Navigazione nella pagina dei post di blog", "description": "The ARIA label for the blog posts pagination" }, "theme.blog.post.paginator.newerPost": { - "message": "Newer Post", + "message": "Articolo più recente", "description": "The blog post button label to navigate to the newer/previous post" }, "theme.blog.post.paginator.olderPost": { - "message": "Older Post", + "message": "Articolo precedente", "description": "The blog post button label to navigate to the older/next post" }, "theme.blog.sidebar.navAriaLabel": { - "message": "Recent blog posts navigation", + "message": "Navigazione tra i post recenti del blog", "description": "The ARIA label for recent posts in the blog sidebar" }, "theme.tags.tagsPageTitle": { - "message": "Tags", + "message": "Tag", "description": "The title of the tag list page" }, "theme.blog.post.plurals": { - "message": "One post|{count} posts", + "message": "Un post|{count} post", "description": "Pluralized label for \"{count} posts\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.blog.tagTitle": { - "message": "{nPosts} tagged with \"{tagName}\"", + "message": "{nPosts} taggati come \"{tagName}\"", "description": "The title of the page for a blog tag" }, "theme.tags.tagsPageLink": { - "message": "View All Tags", + "message": "Visualizza tutti i tag", "description": "The label of the link targeting the tag list page" }, "theme.CodeBlock.copyButtonAriaLabel": { - "message": "Copy code to clipboard", + "message": "Copia codice negli appunti", "description": "The ARIA label for copy code blocks button" }, "theme.CodeBlock.copied": { - "message": "Copied", + "message": "Copiato", "description": "The copied button label on code blocks" }, "theme.CodeBlock.copy": { - "message": "Copy", + "message": "Copia", "description": "The copy button label on code blocks" }, "theme.docs.sidebar.expandButtonTitle": { - "message": "Expand sidebar", + "message": "Espandi la barra laterale", "description": "The ARIA label and title attribute for expand button of doc sidebar" }, "theme.docs.sidebar.expandButtonAriaLabel": { - "message": "Expand sidebar", + "message": "Espandi la barra laterale", "description": "The ARIA label and title attribute for expand button of doc sidebar" }, "theme.docs.paginator.navAriaLabel": { - "message": "Docs pages navigation", + "message": "Navigazione tra le pagine della documentazione", "description": "The ARIA label for the docs pagination" }, "theme.docs.paginator.previous": { - "message": "Previous", + "message": "Precedente", "description": "The label used to navigate to the previous doc" }, "theme.docs.paginator.next": { - "message": "Next", + "message": "Prossimo", "description": "The label used to navigate to the next doc" }, "theme.docs.sidebar.collapseButtonTitle": { - "message": "Collapse sidebar", + "message": "Comprimi la barra laterale", "description": "The title attribute for collapse button of doc sidebar" }, "theme.docs.sidebar.collapseButtonAriaLabel": { - "message": "Collapse sidebar", + "message": "Comprimi la barra laterale", "description": "The title attribute for collapse button of doc sidebar" }, "theme.docs.versions.unreleasedVersionLabel": { - "message": "This is unreleased documentation for {siteTitle} {versionLabel} version.", + "message": "Questa è una documentazione non rilasciata per la versione {versionLabel} di {siteTitle}.", "description": "The label used to tell the user that he's browsing an unreleased doc version" }, "theme.docs.versions.unmaintainedVersionLabel": { - "message": "This is documentation for {siteTitle} {versionLabel}, which is no longer actively maintained.", + "message": "Questa è la documentazione per la versione {versionLabel} di {siteTitle}, che non è più mantenuta attivamente.", "description": "The label used to tell the user that he's browsing an unmaintained doc version" }, "theme.docs.versions.latestVersionSuggestionLabel": { - "message": "For up-to-date documentation, see the {latestVersionLink} ({versionLabel}).", + "message": "Per la documentazione aggiornata, visualizza l'{latestVersionLink} ({versionLabel}).", "description": "The label used to tell the user to check the latest version" }, "theme.docs.versions.latestVersionLinkLabel": { - "message": "latest version", + "message": "ultima versione", "description": "The label used for the latest version suggestion link label" }, "theme.common.editThisPage": { - "message": "Edit this page", + "message": "Modifica questa pagina", "description": "The link label to edit the current page" }, "theme.common.headingLinkTitle": { - "message": "Direct link to heading", + "message": "Link diretto all'intestazione", "description": "Title for link to heading" }, "theme.lastUpdated.atDate": { - "message": " on {date}", + "message": " il {date}", "description": "The words used to describe on which date a page has been last updated" }, "theme.lastUpdated.byUser": { - "message": " by {user}", + "message": " da {user}", "description": "The words used to describe by who the page has been last updated" }, "theme.lastUpdated.lastUpdatedAtBy": { - "message": "Last updated{atDate}{byUser}", + "message": "Ultimo aggiornamento {atDate}{byUser}", "description": "The sentence used to display when a page has been last updated, and by who" }, "theme.navbar.mobileSidebarSecondaryMenu.backButtonLabel": { - "message": "← Back to main menu", + "message": "← Torna al menu principale", "description": "The label of the back button to return to main menu, inside the mobile navbar sidebar secondary menu (notably used to display the docs sidebar)" }, "theme.common.skipToMainContent": { - "message": "Skip to main content", + "message": "Salta al contenuto principale", "description": "The skip to content label used for accessibility, allowing to rapidly navigate to main content with keyboard tab/enter navigation" }, "theme.TOCCollapsible.toggleButtonLabel": { - "message": "On this page", + "message": "Su questa pagina", "description": "The label used by the button on the collapsible TOC component" }, "theme.ErrorPageContent.title": { - "message": "This page crashed.", + "message": "Questa pagina si è bloccata.", "description": "The title of the fallback page when the page crashed" }, "theme.ErrorPageContent.tryAgain": { - "message": "Try again", + "message": "Riprova", "description": "The label of the button to try again rendering when the React error boundary captures an error" }, "theme.BackToTopButton.buttonAriaLabel": { - "message": "Scroll back to top", + "message": "Torna in cima", "description": "The ARIA label for the back to top button" }, "theme.blog.archive.title": { - "message": "Archive", + "message": "Archivio", "description": "The page & hero title of the blog archive page" }, "theme.blog.archive.description": { - "message": "Archive", + "message": "Archivio", "description": "The page & hero description of the blog archive page" }, "theme.blog.post.readMoreLabel": { - "message": "Read more about {title}", + "message": "Leggi di più su {title}", "description": "The ARIA label for the link to full blog posts from excerpts" }, "theme.colorToggle.ariaLabel": { - "message": "Switch between dark and light mode (currently {mode})", + "message": "Cambia modalità tra scura e chiara (correntemente {mode})", "description": "The ARIA label for the color mode toggle" }, "theme.colorToggle.ariaLabel.mode.dark": { - "message": "dark mode", + "message": "modalità scura", "description": "The name for the dark color mode" }, "theme.colorToggle.ariaLabel.mode.light": { - "message": "light mode", + "message": "modalità chiara", "description": "The name for the light color mode" }, "theme.docs.breadcrumbs.home": { - "message": "Home page", + "message": "Pagina Home", "description": "The ARIA label for the home page in the breadcrumbs" }, "theme.docs.breadcrumbs.navAriaLabel": { - "message": "Breadcrumbs", + "message": "Breadcrumb", "description": "The ARIA label for the breadcrumbs" }, "theme.docs.DocCard.categoryDescription": { - "message": "{count} items", + "message": "{count} elementi", "description": "The default description for a category card in the generated index about how many items this category includes" }, "theme.docs.tagDocListPageTitle.nDocsTagged": { - "message": "One doc tagged|{count} docs tagged", + "message": "Una documentazione etichettata|{count} documentazioni etichettate", "description": "Pluralized label for \"{count} docs tagged\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.docs.tagDocListPageTitle": { - "message": "{nDocsTagged} with \"{tagName}\"", + "message": "{nDocsTagged} con \"{tagName}\"", "description": "The title of the page for a docs tag" }, "theme.docs.versionBadge.label": { - "message": "Version: {versionLabel}" + "message": "Versione: {versionLabel}" }, "theme.navbar.mobileVersionsDropdown.label": { - "message": "Versions", + "message": "Versioni", "description": "The label for the navbar versions dropdown on mobile view" }, "theme.CodeBlock.wordWrapToggle": { - "message": "Toggle word wrap", + "message": "Attiva/Disattiva avvolgimento parola", "description": "The title attribute for toggle word wrapping button of code block lines" }, "theme.DocSidebarItem.toggleCollapsedCategoryAriaLabel": { - "message": "Toggle the collapsible sidebar category '{label}'", + "message": "Attiva/Disattiva la categoria della barra laterale comprimibile '{label}'", "description": "The ARIA label to toggle the collapsible sidebar category" }, "theme.navbar.mobileLanguageDropdown.label": { - "message": "Languages", + "message": "Lingue", "description": "The label for the mobile language switcher dropdown" }, "theme.IdealImageMessage.loading": { - "message": "Loading...", + "message": "Caricamento...", "description": "When the full-scale image is loading" }, "theme.IdealImageMessage.load": { - "message": "Click to load{sizeMessage}", + "message": "Clicca per caricare {sizeMessage}", "description": "To prompt users to load the full image. sizeMessage is a parenthesized size figure." }, "theme.IdealImageMessage.offline": { - "message": "Your browser is offline. Image not loaded", + "message": "Il tuo browser è offline. Immagine non caricata", "description": "When the user is viewing an offline document" }, "theme.IdealImageMessage.404error": { - "message": "404. Image not found", + "message": "404. Immagine non trovata", "description": "When the image is not found" }, "theme.IdealImageMessage.error": { - "message": "Error. Click to reload", + "message": "Errore. Clicca per ricaricare", "description": "When the image fails to load for unknown error" }, "theme.SearchBar.noResultsText": { - "message": "No results" + "message": "Nessun risultato" }, "theme.SearchBar.seeAll": { - "message": "See all results" + "message": "Visualizza tutti i risultati" }, "theme.SearchBar.label": { - "message": "Search", + "message": "Cerca", "description": "The ARIA label and placeholder for search button" }, "theme.SearchPage.existingResultsTitle": { - "message": "Search results for \"{query}\"", + "message": "Risultati di ricerca per \"{query}\"", "description": "The search page title for non-empty query" }, "theme.SearchPage.emptyResultsTitle": { - "message": "Search the documentation", + "message": "Cerca nella documentazione", "description": "The search page title for empty query" }, "theme.SearchPage.documentsFound.plurals": { - "message": "One document found|{count} documents found", + "message": "Un documento trovato | {count} documenti trovati", "description": "Pluralized label for \"{count} documents found\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.SearchPage.noResultsText": { - "message": "No documents were found", + "message": "Nessun documento trovato", "description": "The paragraph for empty search result" }, "theme.SearchPage.inputPlaceholder": { - "message": "Type your search here", + "message": "Digita qui la tua ricerca", "description": "The placeholder for search page input" }, "theme.SearchPage.inputLabel": { - "message": "Search", + "message": "Cerca", "description": "The ARIA label for search page input" }, "theme.SearchPage.algoliaLabel": { - "message": "Search by Typesense", + "message": "Ricerca per Typesense", "description": "The ARIA label for Typesense mention" }, "theme.SearchPage.fetchingNewResults": { - "message": "Fetching new results...", + "message": "Recuperando nuovi risultati...", "description": "The paragraph for fetching new search results" }, "theme.admonition.note": { @@ -341,143 +341,143 @@ "description": "The default label used for the Caution admonition (:::caution)" }, "theme.NavBar.navAriaLabel": { - "message": "Main", + "message": "Princip.", "description": "The ARIA label for the main navigation" }, "theme.docs.sidebar.navAriaLabel": { - "message": "Docs sidebar", + "message": "Barra documentazione", "description": "The ARIA label for the sidebar navigation" }, "theme.docs.sidebar.closeSidebarButtonAriaLabel": { - "message": "Close navigation bar", + "message": "Chiudi barra di navigazione", "description": "The ARIA label for close button of mobile sidebar" }, "theme.docs.sidebar.toggleSidebarButtonAriaLabel": { - "message": "Toggle navigation bar", + "message": "Attiva/Disattiva barra di navigazione", "description": "The ARIA label for hamburger menu button of mobile navigation" }, "theme.SearchPage.typesenseLabel": { - "message": "Search by Typesense", + "message": "Ricerca per Typesense", "description": "The ARIA label for Typesense mention" }, "theme.SearchModal.searchBox.resetButtonTitle": { - "message": "Clear the query", + "message": "Cancella la richiesta", "description": "The label and ARIA label for search box reset button" }, "theme.SearchModal.searchBox.cancelButtonText": { - "message": "Cancel", + "message": "Annulla", "description": "The label and ARIA label for search box cancel button" }, "theme.SearchModal.startScreen.recentSearchesTitle": { - "message": "Recent", + "message": "Recenti", "description": "The title for recent searches" }, "theme.SearchModal.startScreen.noRecentSearchesText": { - "message": "No recent searches", + "message": "Nessuna ricerca recente", "description": "The text when no recent searches" }, "theme.SearchModal.startScreen.saveRecentSearchButtonTitle": { - "message": "Save this search", + "message": "Salva questa ricerca", "description": "The label for save recent search button" }, "theme.SearchModal.startScreen.removeRecentSearchButtonTitle": { - "message": "Remove this search from history", + "message": "Rimuovi questa ricerca dalla cronologia", "description": "The label for remove recent search button" }, "theme.SearchModal.startScreen.favoriteSearchesTitle": { - "message": "Favorite", + "message": "Preferiti", "description": "The title for favorite searches" }, "theme.SearchModal.startScreen.removeFavoriteSearchButtonTitle": { - "message": "Remove this search from favorites", + "message": "Rimuovi questa ricerca dai preferiti", "description": "The label for remove favorite search button" }, "theme.SearchModal.errorScreen.titleText": { - "message": "Unable to fetch results", + "message": "Impossibile recuperare i risultati", "description": "The title for error screen of search modal" }, "theme.SearchModal.errorScreen.helpText": { - "message": "You might want to check your network connection.", + "message": "Potresti voler verificare la tua connessione di rete.", "description": "The help text for error screen of search modal" }, "theme.SearchModal.footer.selectText": { - "message": "to select", + "message": "per selezionare", "description": "The explanatory text of the action for the enter key" }, "theme.SearchModal.footer.selectKeyAriaLabel": { - "message": "Enter key", + "message": "Tasto Invio", "description": "The ARIA label for the Enter key button that makes the selection" }, "theme.SearchModal.footer.navigateText": { - "message": "to navigate", + "message": "per navigare", "description": "The explanatory text of the action for the Arrow up and Arrow down key" }, "theme.SearchModal.footer.navigateUpKeyAriaLabel": { - "message": "Arrow up", + "message": "Freccia su", "description": "The ARIA label for the Arrow up key button that makes the navigation" }, "theme.SearchModal.footer.navigateDownKeyAriaLabel": { - "message": "Arrow down", + "message": "Freccia giù", "description": "The ARIA label for the Arrow down key button that makes the navigation" }, "theme.SearchModal.footer.closeText": { - "message": "to close", + "message": "per chiudere", "description": "The explanatory text of the action for Escape key" }, "theme.SearchModal.footer.closeKeyAriaLabel": { - "message": "Escape key", + "message": "Tasto ESC", "description": "The ARIA label for the Escape key button that close the modal" }, "theme.SearchModal.footer.searchByText": { - "message": "Search by", + "message": "Cerca per", "description": "The text explain that the search is making by Algolia" }, "theme.SearchModal.noResultsScreen.noResultsText": { - "message": "No results for", + "message": "Nessun risultato per", "description": "The text explains that there are no results for the following search" }, "theme.SearchModal.noResultsScreen.suggestedQueryText": { - "message": "Try searching for", + "message": "Prova a cercare", "description": "The text for the suggested query when no results are found for the following search" }, "theme.SearchModal.noResultsScreen.reportMissingResultsText": { - "message": "Believe this query should return results?", + "message": "Credi che questa richiesta dovrebbe restituire dei risultati?", "description": "The text for the question where the user thinks there are missing results" }, "theme.SearchModal.noResultsScreen.reportMissingResultsLinkText": { - "message": "Let us know.", + "message": "Faccelo sapere.", "description": "The text for the link to report missing results" }, "theme.SearchModal.placeholder": { - "message": "Search docs", + "message": "Cerca documentazione", "description": "The placeholder of the input of the DocSearch pop-up modal" }, "theme.colorToggle.ariaLabel.mode.system": { - "message": "system mode", + "message": "modalità di sistema", "description": "The name for the system color mode" }, "theme.admonition.warning": { - "message": "warning", + "message": "avviso", "description": "The default label used for the Warning admonition (:::warning)" }, "theme.DocSidebarItem.expandCategoryAriaLabel": { - "message": "Expand sidebar category '{label}'", + "message": "Espandi la categoria della barra laterale '{label}'", "description": "The ARIA label to expand the sidebar category" }, "theme.DocSidebarItem.collapseCategoryAriaLabel": { - "message": "Collapse sidebar category '{label}'", + "message": "Comprimi la categoria della barra laterale '{label}'", "description": "The ARIA label to collapse the sidebar category" }, "theme.IconExternalLink.ariaLabel": { - "message": "(opens in new tab)", + "message": "(si apre in una nuova scheda)", "description": "The ARIA label for the external link icon" }, "theme.navbar.mobileDropdown.collapseButton.expandAriaLabel": { - "message": "Expand the dropdown", + "message": "Espandi il menu' a tendina", "description": "The ARIA label of the button to expand the mobile dropdown navbar item" }, "theme.navbar.mobileDropdown.collapseButton.collapseAriaLabel": { - "message": "Collapse the dropdown", + "message": "Comprimi il menu' a tendina", "description": "The ARIA label of the button to collapse the mobile dropdown navbar item" }, "theme.blog.author.pageTitle": { @@ -485,35 +485,35 @@ "description": "The title of the page for a blog author" }, "theme.blog.authorsList.pageTitle": { - "message": "Authors", + "message": "Autori", "description": "The title of the authors page" }, "theme.blog.authorsList.viewAll": { - "message": "View all authors", + "message": "Vedi tutti gli autori", "description": "The label of the link targeting the blog authors page" }, "theme.blog.author.noPosts": { - "message": "This author has not written any posts yet.", + "message": "Questo autore non ha ancora scritto nessun affisso.", "description": "The text for authors with 0 blog post" }, "theme.contentVisibility.unlistedBanner.title": { - "message": "Unlisted page", + "message": "Pagina non in lista", "description": "The unlisted content banner title" }, "theme.contentVisibility.unlistedBanner.message": { - "message": "This page is unlisted. Search engines will not index it, and only users having a direct link can access it.", + "message": "Questa pagina non è elencata. I motori di ricerca non la indicizzeranno e solo gli utenti che dispongono di un collegamento diretto possono accedervi.", "description": "The unlisted content banner message" }, "theme.contentVisibility.draftBanner.title": { - "message": "Draft page", + "message": "Pagina in bozza", "description": "The draft content banner title" }, "theme.contentVisibility.draftBanner.message": { - "message": "This page is a draft. It will only be visible in dev and be excluded from the production build.", + "message": "Questa pagina è una bozza. Sarà visibile solo in dev e sarà esclusa dal rilascio della produzione.", "description": "The draft content banner message" }, "theme.docs.DocCard.categoryDescription.plurals": { - "message": "1 item|{count} items", + "message": "1 voce|{count} voci", "description": "The default description for a category card in the generated index about how many items this category includes" } } diff --git a/i18n/it/docusaurus-plugin-content-docs/current.json b/i18n/it/docusaurus-plugin-content-docs/current.json index 9b826ed21..2a86928ad 100644 --- a/i18n/it/docusaurus-plugin-content-docs/current.json +++ b/i18n/it/docusaurus-plugin-content-docs/current.json @@ -1,6 +1,6 @@ { "version.label": { - "message": "Next", + "message": "Prossimo", "description": "The label for version current" }, "sidebar.sidebar.category.General": { diff --git a/i18n/it/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/it/docusaurus-plugin-content-docs/current/general/dns-providers.md index 15ca7e547..794261475 100644 --- a/i18n/it/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/it/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### Non-filtering - -| Protocol | Address | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| Protocol | Address | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Ad + malware blocking - -| Protocol | Address | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Ad + malware + social media blocking - -| Protocol | Address | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Ad + malware + adult + gambling blocking - -| Protocol | Address | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Ad + malware + adult + gambling + social media blocking - -| Protocol | Address | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### Unsecured -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protocol | Address | | | -------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/it/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md b/i18n/it/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md index e0bdd29f3..26f603232 100644 --- a/i18n/it/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md +++ b/i18n/it/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md @@ -9,7 +9,7 @@ DNS-over-HTTPS con autenticazione consente di impostare un nome utente e una pas Questo aiuta a prevenire accessi non autorizzati e migliora la sicurezza. Inoltre, puoi limitare l'uso di altri protocolli per profili specifici. Questa funzione è particolarmente utile quando l'indirizzo del tuo server DNS è noto ad altri. Aggiungendo una password, puoi bloccare l'accesso e assicurarti che solo tu possa utilizzarlo. -## Come configurarlo +## How to set it up :::note Compatibilità diff --git a/i18n/it/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md b/i18n/it/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md index 13d3151a4..76dc4d9f0 100644 --- a/i18n/it/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md +++ b/i18n/it/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md @@ -7,7 +7,7 @@ Configurando le impostazioni di accesso, puoi proteggere il tuo AdGuard DNS da a Le richieste bloccate non verranno visualizzate nel registro delle query e non sono conteggiate nel limite totale. -## Come configurarlo +## How to set it up ### Clienti consentiti diff --git a/i18n/it/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/it/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index 7d2069239..92f06ae16 100644 --- a/i18n/it/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/it/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,48 +3,58 @@ title: Controllo parentale sidebar_position: 5 --- -## Cos'è +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. -Il controllo parentale è un insieme di impostazioni che ti offre la flessibilità di personalizzare l'accesso a determinati siti web con contenuti "sensibili". Puoi utilizzare questa funzionalità per limitare l'accesso dei tuoi figli a siti per adulti, personalizzare le query di ricerca, bloccare l'uso di servizi popolari e altro ancora. +## How to set it up -## Come configurarlo +You can flexibly configure all features on your servers, including the parental control feature. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. -Puoi configurare in modo flessibile tutte le funzionalità sui tuoi server, inclusa la funzionalità di controllo genitori. [Nell'articolo corrispondente](private-dns/server-and-settings/server-and-settings.md), puoi familiarizzare con cosa sia un "server" in AdGuard DNS e imparare come creare diversi server con diversi insiemi di impostazioni. +Then, go to the settings of the selected server and enable the required configurations. -Poi, vai alle impostazioni del server selezionato e abilita le configurazioni richieste. +### Block adult websites -### Bloccare i siti web per adulti +Blocks websites with inappropriate and adult content. -Blocca i siti web con contenuti inappropriati e per adulti. +![Blocked website \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) -![Sito web bloccato \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) +### Safe search -### Ricerca sicura +Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -Rimuove risultati inappropriati da Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave ed Ecosia. +### YouTube restricted mode -![Ricerca sicura \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) +Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -### Modalità ristretta di YouTube +### Blocked services and websites -Rimuove l'opzione di visualizzare e postare commenti sotto i video e interagire con contenuti 18+ su YouTube. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. -![Modalità ristretta \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) +![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) -### Servizi e siti web bloccati +### Block websites by category -AdGuard DNS blocca l'accesso a servizi popolari con un clic. È utile se non vuoi che i dispositivi connessi visitino Instagram e YouTube, ad esempio. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. -![Servizi bloccati \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) -### Blocca i siti web per categoria +### Pause schedule -Questa funzione consente di limitare l'accesso a specifiche categorie di siti web scegliendo tra più di 20 categorie, inclusi _Contenuti per adulti_, _Giochi_, _Bancheggio_ e _Comunicazione_. Ad esempio, se blocchi i siti che contengono informazioni su alcol, tabacco o droghe, il dispositivo selezionato non potrà più aprire le pagine che rientrano in quelle categorie. +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. -![Bloccaggio basato su categoria \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. -### Pianifica una pausa +To set up a pause schedule: -Abilita i controlli parentali nei giorni selezionati con un intervallo di tempo specificato. Ad esempio, puoi aver consentito a tuo figlio di guardare video di YouTube solo fino alle 23:00 nei giorni feriali. Ma nei fine settimana, questo accesso non è limitato. Personalizza il programma a tuo piacimento e blocca l'accesso a siti selezionati durante le ore che desideri. +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. -![Programma \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. + +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) + +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. + +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. + +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index d4e19fd45..9cdceb6c7 100644 --- a/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ Queste sono ulteriormente suddivise in sottocategorie: - **CDN**: richiesta connessa a Content Delivery Network (CDN), una rete globale di server proxy che accelera la consegna dei contenuti agli utenti finali - **Altro** -### Aziende maggiori +## Aziende maggiori In questa tabella, non mostriamo solo i nomi delle aziende più visitate o più bloccate, ma visualizziamo anche informazioni su quali domini sono stati richiesti oppure quali domini sono stati bloccati di più. diff --git a/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..35c123d3f --- /dev/null +++ b/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Obbligatorio | Descrizione | Example | +| :---------------- | :------------ | :----------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | No | Detected account ID, if any. | `1234` | +| `DnsServerId` | string | No | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | string | No | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | string | No | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | string | No | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | string | Sì | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | string | No | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | string | No | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Sì | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | No | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Sì | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Sì | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Sì | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Sì | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Sì | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Sì | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Sì | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | string | No | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Sì | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Sì | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## FAQ + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 5440c3eb9..ab792f475 100644 --- a/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Registro delle richieste sidebar_position: 5 --- -## Cos'è il registro delle richieste +## What is Query log? -Il registro delle richieste è uno strumento utile per lavorare con AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. Ti consente di visualizzare tutte le richieste effettuate dai tuoi dispositivi durante il periodo selezionato e di ordinare le richieste per stato, tipo, azienda, dispositivo, paese. ## Come si usa -Ecco cosa puoi vedere e cosa puoi fare nel _Registro richieste_. +Here’s what you can see and what you can do in _Query log_. ### Informazioni dettagliate sulle richieste -![Info sulle richieste \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Blocco e sblocco di domini Le richieste possono essere bloccate e sbloccate senza lasciare il registro, utilizzando gli strumenti disponibili. -![Sblocca dominio \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Ordinamento delle richieste diff --git a/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index 88195ac8c..0b6ae2bcf 100644 --- a/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/it/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS fornisce un ampio intervallo di strumenti utili per il monitoraggio - [Destinazione del traffico](/private-dns/statistics-and-log/traffic-destination.md) - [Aziende](/private-dns/statistics-and-log/companies.md) - [Registro delle query](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/ja/code.json b/i18n/ja/code.json index d511d5a1e..3106103ec 100644 --- a/i18n/ja/code.json +++ b/i18n/ja/code.json @@ -8,476 +8,476 @@ "description": "The site tagline used in meta description" }, "apiChangelog.loading": { - "message": "Loading changelog…", + "message": "変更履歴を読み込んでいます…", "description": "Placeholder shown while the API changelog is being loaded" }, "apiChangelog.error": { - "message": "Failed to load the changelog. You can view the original at {link}.", + "message": "変更履歴を読み込めませんでした。{link}で原文を確認できます。", "description": "Error message shown when the API changelog cannot be loaded. {link} is a link to the original changelog on adguard-dns.io" }, "apiChangelog.versions": { - "message": "Versions", + "message": "バージョン履歴", "description": "Accessible name of the version list sidebar on the API changelog page" }, "apiReference.loading": { - "message": "Loading API reference…", + "message": "APIリファレンスを読み込んでいます…", "description": "Placeholder shown while the API reference (Swagger UI) is being loaded" }, "theme.NotFound.title": { - "message": "Page Not Found", + "message": "ページが見つかりません", "description": "The title of the 404 page" }, "theme.NotFound.p1": { - "message": "We could not find what you were looking for.", + "message": "お探しのものが見つかりませんでした。", "description": "The first paragraph of the 404 page" }, "theme.NotFound.p2": { - "message": "Please contact the owner of the site that linked you to the original URL and let them know their link is broken.", + "message": "リンク元のサイトの運営者に連絡し、リンクが切れていることをお知らせください。", "description": "The 2nd paragraph of the 404 page" }, "theme.AnnouncementBar.closeButtonAriaLabel": { - "message": "Close", + "message": "閉じる", "description": "The ARIA label for close button of announcement bar" }, "theme.blog.paginator.navAriaLabel": { - "message": "Blog list page navigation", + "message": "ブログリストページナビゲーション", "description": "The ARIA label for the blog pagination" }, "theme.blog.paginator.newerEntries": { - "message": "Newer Entries", + "message": "新着記事", "description": "The label used to navigate to the newer blog posts page (previous page)" }, "theme.blog.paginator.olderEntries": { - "message": "Older Entries", + "message": "古い記事", "description": "The label used to navigate to the older blog posts page (next page)" }, "theme.blog.post.readingTime.plurals": { - "message": "One min read|{readingTime} min read", + "message": "この記事は1分で読めます|この記事は{readingTime}分で読めます", "description": "Pluralized label for \"{readingTime} min read\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.tags.tagsListLabel": { - "message": "Tags:", + "message": "タグ:", "description": "The label alongside a tag list" }, "theme.blog.post.readMore": { - "message": "Read More", + "message": "全文を読む", "description": "The label used in blog post item excerpts to link to full blog posts" }, "theme.blog.post.paginator.navAriaLabel": { - "message": "Blog post page navigation", + "message": "ブログ投稿ページナビゲーション", "description": "The ARIA label for the blog posts pagination" }, "theme.blog.post.paginator.newerPost": { - "message": "Newer Post", + "message": "より新しい投稿へ", "description": "The blog post button label to navigate to the newer/previous post" }, "theme.blog.post.paginator.olderPost": { - "message": "Older Post", + "message": "より古い投稿へ", "description": "The blog post button label to navigate to the older/next post" }, "theme.blog.sidebar.navAriaLabel": { - "message": "Recent blog posts navigation", + "message": "最近のブログ記事のナビゲーション", "description": "The ARIA label for recent posts in the blog sidebar" }, "theme.tags.tagsPageTitle": { - "message": "Tags", + "message": "タグ", "description": "The title of the tag list page" }, "theme.blog.post.plurals": { - "message": "One post|{count} posts", + "message": "1件の投稿|{count}件の投稿", "description": "Pluralized label for \"{count} posts\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.blog.tagTitle": { - "message": "{nPosts} tagged with \"{tagName}\"", + "message": "\"{tagName}\"タグの投稿: {nPosts}件", "description": "The title of the page for a blog tag" }, "theme.tags.tagsPageLink": { - "message": "View All Tags", + "message": "タグをすべて見る", "description": "The label of the link targeting the tag list page" }, "theme.CodeBlock.copyButtonAriaLabel": { - "message": "Copy code to clipboard", + "message": "クリップボードにコードをコピー", "description": "The ARIA label for copy code blocks button" }, "theme.CodeBlock.copied": { - "message": "Copied", + "message": "コピー済み", "description": "The copied button label on code blocks" }, "theme.CodeBlock.copy": { - "message": "Copy", + "message": "コピー", "description": "The copy button label on code blocks" }, "theme.docs.sidebar.expandButtonTitle": { - "message": "Expand sidebar", + "message": "サイドバーを拡張する", "description": "The ARIA label and title attribute for expand button of doc sidebar" }, "theme.docs.sidebar.expandButtonAriaLabel": { - "message": "Expand sidebar", + "message": "サイドバーを拡張する", "description": "The ARIA label and title attribute for expand button of doc sidebar" }, "theme.docs.paginator.navAriaLabel": { - "message": "Docs pages navigation", + "message": "Docsページのナビゲーション", "description": "The ARIA label for the docs pagination" }, "theme.docs.paginator.previous": { - "message": "Previous", + "message": "前のドキュメント", "description": "The label used to navigate to the previous doc" }, "theme.docs.paginator.next": { - "message": "Next", + "message": "次のドキュメント", "description": "The label used to navigate to the next doc" }, "theme.docs.sidebar.collapseButtonTitle": { - "message": "Collapse sidebar", + "message": "サイドバーを折りたたむ", "description": "The title attribute for collapse button of doc sidebar" }, "theme.docs.sidebar.collapseButtonAriaLabel": { - "message": "Collapse sidebar", + "message": "サイドバーを折りたたむ", "description": "The title attribute for collapse button of doc sidebar" }, "theme.docs.versions.unreleasedVersionLabel": { - "message": "This is unreleased documentation for {siteTitle} {versionLabel} version.", + "message": "こちらは {siteTitle} v{versionLabel} のための未公開ドキュメントです。", "description": "The label used to tell the user that he's browsing an unreleased doc version" }, "theme.docs.versions.unmaintainedVersionLabel": { - "message": "This is documentation for {siteTitle} {versionLabel}, which is no longer actively maintained.", + "message": "こちらは、 {siteTitle} v{versionLabel} (もうメンテナンスされていない)のためのドキュメントです。", "description": "The label used to tell the user that he's browsing an unmaintained doc version" }, "theme.docs.versions.latestVersionSuggestionLabel": { - "message": "For up-to-date documentation, see the {latestVersionLink} ({versionLabel}).", + "message": "最新のドキュメンテーションは、 {latestVersionLink} (v{versionLabel}) をご覧ください。", "description": "The label used to tell the user to check the latest version" }, "theme.docs.versions.latestVersionLinkLabel": { - "message": "latest version", + "message": "最新バージョン", "description": "The label used for the latest version suggestion link label" }, "theme.common.editThisPage": { - "message": "Edit this page", + "message": "このページを編集する", "description": "The link label to edit the current page" }, "theme.common.headingLinkTitle": { - "message": "Direct link to heading", + "message": "見出しへの直リンク", "description": "Title for link to heading" }, "theme.lastUpdated.atDate": { - "message": " on {date}", + "message": " 最終更新日: {date}", "description": "The words used to describe on which date a page has been last updated" }, "theme.lastUpdated.byUser": { - "message": " by {user}", + "message": " 更新者: {user}", "description": "The words used to describe by who the page has been last updated" }, "theme.lastUpdated.lastUpdatedAtBy": { - "message": "Last updated{atDate}{byUser}", + "message": "{atDate} {byUser}", "description": "The sentence used to display when a page has been last updated, and by who" }, "theme.navbar.mobileSidebarSecondaryMenu.backButtonLabel": { - "message": "← Back to main menu", + "message": "← メインメニューに戻る", "description": "The label of the back button to return to main menu, inside the mobile navbar sidebar secondary menu (notably used to display the docs sidebar)" }, "theme.common.skipToMainContent": { - "message": "Skip to main content", + "message": "メインコンテンツへスキップする", "description": "The skip to content label used for accessibility, allowing to rapidly navigate to main content with keyboard tab/enter navigation" }, "theme.TOCCollapsible.toggleButtonLabel": { - "message": "On this page", + "message": "このページの目次", "description": "The label used by the button on the collapsible TOC component" }, "theme.ErrorPageContent.title": { - "message": "This page crashed.", + "message": "このページはクラッシュしました。", "description": "The title of the fallback page when the page crashed" }, "theme.ErrorPageContent.tryAgain": { - "message": "Try again", + "message": "再試行する", "description": "The label of the button to try again rendering when the React error boundary captures an error" }, "theme.BackToTopButton.buttonAriaLabel": { - "message": "Scroll back to top", + "message": "スクロールしてトップに戻る", "description": "The ARIA label for the back to top button" }, "theme.blog.archive.title": { - "message": "Archive", + "message": "アーカイブ", "description": "The page & hero title of the blog archive page" }, "theme.blog.archive.description": { - "message": "Archive", + "message": "アーカイブ", "description": "The page & hero description of the blog archive page" }, "theme.blog.post.readMoreLabel": { - "message": "Read more about {title}", + "message": "{title}の全文を読む", "description": "The ARIA label for the link to full blog posts from excerpts" }, "theme.colorToggle.ariaLabel": { - "message": "Switch between dark and light mode (currently {mode})", + "message": "ダークモードとライトモードの切り替え(現在: {mode})", "description": "The ARIA label for the color mode toggle" }, "theme.colorToggle.ariaLabel.mode.dark": { - "message": "dark mode", + "message": "ダークモード", "description": "The name for the dark color mode" }, "theme.colorToggle.ariaLabel.mode.light": { - "message": "light mode", + "message": "ライトモード", "description": "The name for the light color mode" }, "theme.docs.breadcrumbs.home": { - "message": "Home page", + "message": "ホームページ", "description": "The ARIA label for the home page in the breadcrumbs" }, "theme.docs.breadcrumbs.navAriaLabel": { - "message": "Breadcrumbs", + "message": "パンくずリスト", "description": "The ARIA label for the breadcrumbs" }, "theme.docs.DocCard.categoryDescription": { - "message": "{count} items", + "message": "アイテム数: {count}", "description": "The default description for a category card in the generated index about how many items this category includes" }, "theme.docs.tagDocListPageTitle.nDocsTagged": { - "message": "One doc tagged|{count} docs tagged", + "message": "タグ付けされたドキュメント数: 1件|タグ付けされたドキュメント数: {count}件", "description": "Pluralized label for \"{count} docs tagged\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.docs.tagDocListPageTitle": { - "message": "{nDocsTagged} with \"{tagName}\"", + "message": "\"{tagName}\"で{nDocsTagged}", "description": "The title of the page for a docs tag" }, "theme.docs.versionBadge.label": { - "message": "Version: {versionLabel}" + "message": "バージョン: {versionLabel}" }, "theme.navbar.mobileVersionsDropdown.label": { - "message": "Versions", + "message": "バージョン履歴", "description": "The label for the navbar versions dropdown on mobile view" }, "theme.CodeBlock.wordWrapToggle": { - "message": "Toggle word wrap", + "message": "ワードラップをトグル", "description": "The title attribute for toggle word wrapping button of code block lines" }, "theme.DocSidebarItem.toggleCollapsedCategoryAriaLabel": { - "message": "Toggle the collapsible sidebar category '{label}'", + "message": "折りたたみ式サイドバーのカテゴリー '{label}' をトグルします。", "description": "The ARIA label to toggle the collapsible sidebar category" }, "theme.navbar.mobileLanguageDropdown.label": { - "message": "Languages", + "message": "言語", "description": "The label for the mobile language switcher dropdown" }, "theme.IdealImageMessage.loading": { - "message": "Loading...", + "message": "読み込み中…", "description": "When the full-scale image is loading" }, "theme.IdealImageMessage.load": { - "message": "Click to load{sizeMessage}", + "message": "クリックでフル画像読み込み{sizeMessage}", "description": "To prompt users to load the full image. sizeMessage is a parenthesized size figure." }, "theme.IdealImageMessage.offline": { - "message": "Your browser is offline. Image not loaded", + "message": "お使いのブラウザはオフラインのため、画像が読み込まれませんでした", "description": "When the user is viewing an offline document" }, "theme.IdealImageMessage.404error": { - "message": "404. Image not found", + "message": "404. 画像が見つかりません", "description": "When the image is not found" }, "theme.IdealImageMessage.error": { - "message": "Error. Click to reload", + "message": "エラー発生。クリックして再読み込み", "description": "When the image fails to load for unknown error" }, "theme.SearchBar.noResultsText": { - "message": "No results" + "message": "結果結果がありません" }, "theme.SearchBar.seeAll": { - "message": "See all results" + "message": "すべての検索結果を表示" }, "theme.SearchBar.label": { - "message": "Search", + "message": "検索", "description": "The ARIA label and placeholder for search button" }, "theme.SearchPage.existingResultsTitle": { - "message": "Search results for \"{query}\"", + "message": "\"{query}\" の検索結果", "description": "The search page title for non-empty query" }, "theme.SearchPage.emptyResultsTitle": { - "message": "Search the documentation", + "message": "ドキュメンテーションで検索", "description": "The search page title for empty query" }, "theme.SearchPage.documentsFound.plurals": { - "message": "One document found|{count} documents found", + "message": "1件のドキュメントが見つかりました|{count}件のドキュメントが見つかりました", "description": "Pluralized label for \"{count} documents found\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.SearchPage.noResultsText": { - "message": "No documents were found", + "message": "ドキュメントが見つかりませんでした", "description": "The paragraph for empty search result" }, "theme.SearchPage.inputPlaceholder": { - "message": "Type your search here", + "message": "ここに検索内容を入力してください", "description": "The placeholder for search page input" }, "theme.SearchPage.inputLabel": { - "message": "Search", + "message": "検索", "description": "The ARIA label for search page input" }, "theme.SearchPage.algoliaLabel": { - "message": "Search by Typesense", + "message": "Typesenseで検索", "description": "The ARIA label for Typesense mention" }, "theme.SearchPage.fetchingNewResults": { - "message": "Fetching new results...", + "message": "新しい検索結果を取得中...", "description": "The paragraph for fetching new search results" }, "theme.admonition.note": { - "message": "note", + "message": "注記", "description": "The default label used for the Note admonition (:::note)" }, "theme.admonition.tip": { - "message": "tip", + "message": "ヒント", "description": "The default label used for the Tip admonition (:::tip)" }, "theme.admonition.danger": { - "message": "danger", + "message": "危険", "description": "The default label used for the Danger admonition (:::danger)" }, "theme.admonition.info": { - "message": "info", + "message": "お知らせ", "description": "The default label used for the Info admonition (:::info)" }, "theme.admonition.caution": { - "message": "caution", + "message": "注意", "description": "The default label used for the Caution admonition (:::caution)" }, "theme.NavBar.navAriaLabel": { - "message": "Main", + "message": "メインナビゲーション", "description": "The ARIA label for the main navigation" }, "theme.docs.sidebar.navAriaLabel": { - "message": "Docs sidebar", + "message": "ドキュメントのサイドバー", "description": "The ARIA label for the sidebar navigation" }, "theme.docs.sidebar.closeSidebarButtonAriaLabel": { - "message": "Close navigation bar", + "message": "ナビゲーションバーを閉じる", "description": "The ARIA label for close button of mobile sidebar" }, "theme.docs.sidebar.toggleSidebarButtonAriaLabel": { - "message": "Toggle navigation bar", + "message": "ナビゲーションバーをトグル", "description": "The ARIA label for hamburger menu button of mobile navigation" }, "theme.SearchPage.typesenseLabel": { - "message": "Search by Typesense", + "message": "Typesenseで検索", "description": "The ARIA label for Typesense mention" }, "theme.SearchModal.searchBox.resetButtonTitle": { - "message": "Clear the query", + "message": "検索クエリをクリアする", "description": "The label and ARIA label for search box reset button" }, "theme.SearchModal.searchBox.cancelButtonText": { - "message": "Cancel", + "message": "キャンセル", "description": "The label and ARIA label for search box cancel button" }, "theme.SearchModal.startScreen.recentSearchesTitle": { - "message": "Recent", + "message": "最近検索した項目", "description": "The title for recent searches" }, "theme.SearchModal.startScreen.noRecentSearchesText": { - "message": "No recent searches", + "message": "最近の検索項目はありません", "description": "The text when no recent searches" }, "theme.SearchModal.startScreen.saveRecentSearchButtonTitle": { - "message": "Save this search", + "message": "この検索を保存する", "description": "The label for save recent search button" }, "theme.SearchModal.startScreen.removeRecentSearchButtonTitle": { - "message": "Remove this search from history", + "message": "この検索結果を検索履歴から削除する", "description": "The label for remove recent search button" }, "theme.SearchModal.startScreen.favoriteSearchesTitle": { - "message": "Favorite", + "message": "お気に入り", "description": "The title for favorite searches" }, "theme.SearchModal.startScreen.removeFavoriteSearchButtonTitle": { - "message": "Remove this search from favorites", + "message": "この検索結果をお気に入りから削除する", "description": "The label for remove favorite search button" }, "theme.SearchModal.errorScreen.titleText": { - "message": "Unable to fetch results", + "message": "検索結果の取得できません", "description": "The title for error screen of search modal" }, "theme.SearchModal.errorScreen.helpText": { - "message": "You might want to check your network connection.", + "message": "ネットワーク接続を確認してください", "description": "The help text for error screen of search modal" }, "theme.SearchModal.footer.selectText": { - "message": "to select", + "message": "選択する", "description": "The explanatory text of the action for the enter key" }, "theme.SearchModal.footer.selectKeyAriaLabel": { - "message": "Enter key", + "message": "Enterキー", "description": "The ARIA label for the Enter key button that makes the selection" }, "theme.SearchModal.footer.navigateText": { - "message": "to navigate", + "message": "ナビゲートする", "description": "The explanatory text of the action for the Arrow up and Arrow down key" }, "theme.SearchModal.footer.navigateUpKeyAriaLabel": { - "message": "Arrow up", + "message": "上矢印", "description": "The ARIA label for the Arrow up key button that makes the navigation" }, "theme.SearchModal.footer.navigateDownKeyAriaLabel": { - "message": "Arrow down", + "message": "下矢印", "description": "The ARIA label for the Arrow down key button that makes the navigation" }, "theme.SearchModal.footer.closeText": { - "message": "to close", + "message": "閉じる", "description": "The explanatory text of the action for Escape key" }, "theme.SearchModal.footer.closeKeyAriaLabel": { - "message": "Escape key", + "message": "Escキー", "description": "The ARIA label for the Escape key button that close the modal" }, "theme.SearchModal.footer.searchByText": { - "message": "Search by", + "message": "検索条件", "description": "The text explain that the search is making by Algolia" }, "theme.SearchModal.noResultsScreen.noResultsText": { - "message": "No results for", + "message": "この検索に対して結果が見つかりません:", "description": "The text explains that there are no results for the following search" }, "theme.SearchModal.noResultsScreen.suggestedQueryText": { - "message": "Try searching for", + "message": "次のキーワードで検索してみる", "description": "The text for the suggested query when no results are found for the following search" }, "theme.SearchModal.noResultsScreen.reportMissingResultsText": { - "message": "Believe this query should return results?", + "message": "この検索で結果が出るはずだと思われる場合", "description": "The text for the question where the user thinks there are missing results" }, "theme.SearchModal.noResultsScreen.reportMissingResultsLinkText": { - "message": "Let us know.", + "message": "ご連絡ください。", "description": "The text for the link to report missing results" }, "theme.SearchModal.placeholder": { - "message": "Search docs", + "message": "全ドキュメントで検索する", "description": "The placeholder of the input of the DocSearch pop-up modal" }, "theme.colorToggle.ariaLabel.mode.system": { - "message": "system mode", + "message": "システムモード", "description": "The name for the system color mode" }, "theme.admonition.warning": { - "message": "warning", + "message": "警告", "description": "The default label used for the Warning admonition (:::warning)" }, "theme.DocSidebarItem.expandCategoryAriaLabel": { - "message": "Expand sidebar category '{label}'", + "message": "サイドバーのカテゴリー「{label}」を展開", "description": "The ARIA label to expand the sidebar category" }, "theme.DocSidebarItem.collapseCategoryAriaLabel": { - "message": "Collapse sidebar category '{label}'", + "message": "サイドバーのカテゴリー「{label}」を折りたたむ", "description": "The ARIA label to collapse the sidebar category" }, "theme.IconExternalLink.ariaLabel": { - "message": "(opens in new tab)", + "message": "(新しいタブで開きます)", "description": "The ARIA label for the external link icon" }, "theme.navbar.mobileDropdown.collapseButton.expandAriaLabel": { - "message": "Expand the dropdown", + "message": "ドロップダウンを展開", "description": "The ARIA label of the button to expand the mobile dropdown navbar item" }, "theme.navbar.mobileDropdown.collapseButton.collapseAriaLabel": { - "message": "Collapse the dropdown", + "message": "ドロップダウンを折りたたむ", "description": "The ARIA label of the button to collapse the mobile dropdown navbar item" }, "theme.blog.author.pageTitle": { @@ -485,35 +485,35 @@ "description": "The title of the page for a blog author" }, "theme.blog.authorsList.pageTitle": { - "message": "Authors", + "message": "著者", "description": "The title of the authors page" }, "theme.blog.authorsList.viewAll": { - "message": "View all authors", + "message": "すべての著者を表示", "description": "The label of the link targeting the blog authors page" }, "theme.blog.author.noPosts": { - "message": "This author has not written any posts yet.", + "message": "この著者はまだ記事を投稿していません。", "description": "The text for authors with 0 blog post" }, "theme.contentVisibility.unlistedBanner.title": { - "message": "Unlisted page", + "message": "限定公開ページ", "description": "The unlisted content banner title" }, "theme.contentVisibility.unlistedBanner.message": { - "message": "This page is unlisted. Search engines will not index it, and only users having a direct link can access it.", + "message": "このページは限定公開です。検索エンジンにはインデックス登録されず、直接リンクを知っているユーザーのみがアクセスできます。", "description": "The unlisted content banner message" }, "theme.contentVisibility.draftBanner.title": { - "message": "Draft page", + "message": "下書きページ", "description": "The draft content banner title" }, "theme.contentVisibility.draftBanner.message": { - "message": "This page is a draft. It will only be visible in dev and be excluded from the production build.", + "message": "このページは下書きです。開発環境でのみ表示され、本番ビルドからは除外されます。", "description": "The draft content banner message" }, "theme.docs.DocCard.categoryDescription.plurals": { - "message": "1 item|{count} items", + "message": "項目数: 1|項目数: {count}", "description": "The default description for a category card in the generated index about how many items this category includes" } } diff --git a/i18n/ja/docusaurus-plugin-content-docs/current.json b/i18n/ja/docusaurus-plugin-content-docs/current.json index b300b32ad..c7e1f46b2 100644 --- a/i18n/ja/docusaurus-plugin-content-docs/current.json +++ b/i18n/ja/docusaurus-plugin-content-docs/current.json @@ -1,6 +1,6 @@ { "version.label": { - "message": "Next", + "message": "次のドキュメント", "description": "The label for version current" }, "sidebar.sidebar.category.General": { diff --git a/i18n/ja/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/ja/docusaurus-plugin-content-docs/current/general/dns-providers.md index 2920ab1f1..b3785495f 100644 --- a/i18n/ja/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/ja/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### AdGuard DNS フィルタリングなし - -| プロトコル | アドレス | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| プロトコル | アドレス | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Ad + malware blocking - -| プロトコル | アドレス | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Ad + malware + social media blocking - -| プロトコル | アドレス | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Ad + malware + adult + gambling blocking - -| プロトコル | アドレス | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Ad + malware + adult + gambling + social media blocking - -| プロトコル | アドレス | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### Unsecured -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | プロトコル | アドレス | | | -------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md b/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md index 1bbd698a1..bd1202e88 100644 --- a/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md +++ b/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md @@ -7,7 +7,7 @@ sidebar_position: 3 ブロックされたリクエストはクエリ ログに表示されず、合計制限にもカウントされません。 -## 設定方法 +## How to set it up ### 許可クライアント diff --git a/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index 101b7fdf1..eb165906c 100644 --- a/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,48 +3,58 @@ title: ペアレンタルコントロール sidebar_position: 5 --- -## ペアレンタルコントロールとは +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. -Parental control is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. +## How to set it up -## 設定方法 +You can flexibly configure all features on your servers, including the parental control feature. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. -ペアレンタルコントロール機能を含め、サーバー上で機能をすべて柔軟に設定できます。 [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. +Then, go to the settings of the selected server and enable the required configurations. -次に、選択したサーバーの設定に移動し、必要な構成を有効にします。 +### Block adult websites -### アダルト系サイトをブロックする - -不適切なコンテンツや成人向けコンテンツのあるウェブサイトをブロックします。 +Blocks websites with inappropriate and adult content. ![Blocked website \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) -### セーフサーチ - -検索エンジン(Google、Bing、DuckDuckGo、Yandex、Pixabay、Brave、Ecosia)で、不適切な検索結果を削除します。 - -![Safe search \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) +### Safe search -### YouTube制限付きモードをオンにする +Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -動画の下でコメントを表示・投稿できないようにし、YouTubeの18禁コンテンツに関わるオプションを無効にします。 +### YouTube restricted mode -![Restricted mode \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) +Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -### ブロックするサービスやWebサイト +### Blocked services and websites -AdGuard DNS は、人気のあるサービスへのアクセスをワンクリックでブロックできます。 It’s useful if you don’t want connected devices to visit Instagram and YouTube, for example. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. ![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) ### Block websites by category -This feature lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. + +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) + +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. + +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### オフタイムを設定する +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -指定された時間間隔で選択した日にペアレンタルコントロールを有効にします。いわゆる「スクリーンタイム」設定のようなものです。 たとえば、子供にYouTube動画の閲覧を平日の21:00までに許可しているとします。 ところが、週末にはこの制限はないとします。 このような場合に、ニーズに合わせてスケジュールをカスタマイズし、希望の時間に選択したサイトへのアクセスをブロックするように設定できます。 +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![Schedule \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index 19cdf96d6..d748410c3 100644 --- a/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ sidebar_position: 4 - **CDN**: エンドユーザーへのコンテンツ配信を高速化するプロキシサーバーの世界的なネットワークであるコンテンツ・デリバリー・ネットワーク(CDN)への接続リクエスト - **その他** -### リクエストが一番多い企業 +## リクエストが一番多い企業 この表では、最もアクセス数の多い企業名や最もブロックされている企業名が表示されるだけでなく、どのドメインからのリクエストが多いか、どのドメインが最もブロックされているかという情報も表示されます。 diff --git a/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..2c97abd0a --- /dev/null +++ b/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Required | Description | Example | +| :---------------- | :------------ | :------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | No | Detected account ID, if any. | `1234` | +| `DnsServerId` | string | No | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | string | No | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | string | No | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | string | No | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | string | Yes | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | string | No | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | string | No | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Yes | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | No | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Yes | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Yes | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Yes | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Yes | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Yes | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Yes | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Yes | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | string | No | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Yes | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Yes | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## FAQ(よくあるご質問) + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 17b6d5bb7..cc4c7aaa6 100644 --- a/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: クエリログ sidebar_position: 5 --- -## 「クエリログ」とは +## What is Query log? -クエリログはAdGuard DNSを使用する際に便利なツールです。 +_Query log_ is a useful tool for working with AdGuard DNS. 指定の期間中にデバイスによって行われたすべてのリクエストを表示し、ステータス、タイプ、企業、デバイス、国別にリクエストを並べ替えることができます。 ## 使い方 -Here’s what you can see and what you can do in the _Query log_. +Here’s what you can see and what you can do in _Query log_. ### 各リクエストの詳細情報 -![Requests info \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### ドメインのブロック・ブロック解除 リクエストは、ログからその場でブロックおよびブロック解除できます。 -![Unblock domain \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### リクエストの並べ替え diff --git a/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index 45b8c7931..aac1071da 100644 --- a/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/ja/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS は、クエリを監視するための便利なツールの幅広 - [トラフィックの送信先](/private-dns/statistics-and-log/traffic-destination.md) - [企業](/private-dns/statistics-and-log/companies.md) - [クエリログ](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/ko/code.json b/i18n/ko/code.json index b4a1feaf7..805833a5a 100644 --- a/i18n/ko/code.json +++ b/i18n/ko/code.json @@ -8,11 +8,11 @@ "description": "The site tagline used in meta description" }, "apiChangelog.loading": { - "message": "Loading changelog…", + "message": "변경 로그를 불러오는 중…", "description": "Placeholder shown while the API changelog is being loaded" }, "apiChangelog.error": { - "message": "Failed to load the changelog. You can view the original at {link}.", + "message": "변경 로그를 불러오지 못했습니다. {link}에서 원본을 확인할 수 있습니다.", "description": "Error message shown when the API changelog cannot be loaded. {link} is a link to the original changelog on adguard-dns.io" }, "apiChangelog.versions": { @@ -20,7 +20,7 @@ "description": "Accessible name of the version list sidebar on the API changelog page" }, "apiReference.loading": { - "message": "Loading API reference…", + "message": "API 레퍼런스를 불러오는 중…", "description": "Placeholder shown while the API reference (Swagger UI) is being loaded" }, "theme.NotFound.title": { @@ -52,7 +52,7 @@ "description": "The label used to navigate to the older blog posts page (next page)" }, "theme.blog.post.readingTime.plurals": { - "message": "One min read|{readingTime} min read", + "message": "읽기에 {readingTime}분 소요", "description": "Pluralized label for \"{readingTime} min read\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.tags.tagsListLabel": { @@ -84,11 +84,11 @@ "description": "The title of the tag list page" }, "theme.blog.post.plurals": { - "message": "One post|{count} posts", + "message": "하나의 포스트|{count}개 포스트들", "description": "Pluralized label for \"{count} posts\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.blog.tagTitle": { - "message": "{nPosts} tagged with \"{tagName}\"", + "message": "{nPosts}가 '{tagName}'로 태그됨", "description": "The title of the page for a blog tag" }, "theme.tags.tagsPageLink": { @@ -136,15 +136,15 @@ "description": "The title attribute for collapse button of doc sidebar" }, "theme.docs.versions.unreleasedVersionLabel": { - "message": "This is unreleased documentation for {siteTitle} {versionLabel} version.", + "message": "본 문서는 아직 출시되지 않은 {siteTitle} {versionLabel} 버전의 문서입니다.", "description": "The label used to tell the user that he's browsing an unreleased doc version" }, "theme.docs.versions.unmaintainedVersionLabel": { - "message": "This is documentation for {siteTitle} {versionLabel}, which is no longer actively maintained.", + "message": "본 문서는 더 이상 적극적으로 유지 관리되지 않는 {siteTitle} {versionLabel}에 대한 문서입니다.", "description": "The label used to tell the user that he's browsing an unmaintained doc version" }, "theme.docs.versions.latestVersionSuggestionLabel": { - "message": "For up-to-date documentation, see the {latestVersionLink} ({versionLabel}).", + "message": "최신 문서는 {latestVersionLink}({versionLabel})에서 확인하세요.", "description": "The label used to tell the user to check the latest version" }, "theme.docs.versions.latestVersionLinkLabel": { @@ -224,19 +224,19 @@ "description": "The ARIA label for the home page in the breadcrumbs" }, "theme.docs.breadcrumbs.navAriaLabel": { - "message": "Breadcrumbs", + "message": "탐색 보조 도구", "description": "The ARIA label for the breadcrumbs" }, "theme.docs.DocCard.categoryDescription": { - "message": "{count} items", + "message": "{count}개 항목", "description": "The default description for a category card in the generated index about how many items this category includes" }, "theme.docs.tagDocListPageTitle.nDocsTagged": { - "message": "One doc tagged|{count} docs tagged", + "message": "{count}개의 문서 중 하나에 태그가 지정됨", "description": "Pluralized label for \"{count} docs tagged\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.docs.tagDocListPageTitle": { - "message": "{nDocsTagged} with \"{tagName}\"", + "message": "{nDocsTagged} ('{tagName}' 포함)", "description": "The title of the page for a docs tag" }, "theme.docs.versionBadge.label": { @@ -247,11 +247,11 @@ "description": "The label for the navbar versions dropdown on mobile view" }, "theme.CodeBlock.wordWrapToggle": { - "message": "Toggle word wrap", + "message": "단어 줄바꿈 전환", "description": "The title attribute for toggle word wrapping button of code block lines" }, "theme.DocSidebarItem.toggleCollapsedCategoryAriaLabel": { - "message": "Toggle the collapsible sidebar category '{label}'", + "message": "사이드바 카테고리 '{label}' 전환", "description": "The ARIA label to toggle the collapsible sidebar category" }, "theme.navbar.mobileLanguageDropdown.label": { @@ -297,7 +297,7 @@ "description": "The search page title for empty query" }, "theme.SearchPage.documentsFound.plurals": { - "message": "One document found|{count} documents found", + "message": "{count}개의 문서를 찾았습니다.", "description": "Pluralized label for \"{count} documents found\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.SearchPage.noResultsText": { @@ -305,7 +305,7 @@ "description": "The paragraph for empty search result" }, "theme.SearchPage.inputPlaceholder": { - "message": "Type your search here", + "message": "여기에 검색어 입력", "description": "The placeholder for search page input" }, "theme.SearchPage.inputLabel": { @@ -313,171 +313,171 @@ "description": "The ARIA label for search page input" }, "theme.SearchPage.algoliaLabel": { - "message": "Search by Typesense", + "message": "Typesense로 검색", "description": "The ARIA label for Typesense mention" }, "theme.SearchPage.fetchingNewResults": { - "message": "Fetching new results...", + "message": "새 결과를 가져오는 중...", "description": "The paragraph for fetching new search results" }, "theme.admonition.note": { - "message": "note", + "message": "주의사항", "description": "The default label used for the Note admonition (:::note)" }, "theme.admonition.tip": { - "message": "tip", + "message": "팁", "description": "The default label used for the Tip admonition (:::tip)" }, "theme.admonition.danger": { - "message": "danger", + "message": "위험", "description": "The default label used for the Danger admonition (:::danger)" }, "theme.admonition.info": { - "message": "info", + "message": "정보", "description": "The default label used for the Info admonition (:::info)" }, "theme.admonition.caution": { - "message": "caution", + "message": "경고", "description": "The default label used for the Caution admonition (:::caution)" }, "theme.NavBar.navAriaLabel": { - "message": "Main", + "message": "메인", "description": "The ARIA label for the main navigation" }, "theme.docs.sidebar.navAriaLabel": { - "message": "Docs sidebar", + "message": "문서 사이드바", "description": "The ARIA label for the sidebar navigation" }, "theme.docs.sidebar.closeSidebarButtonAriaLabel": { - "message": "Close navigation bar", + "message": "탐색 바 닫기", "description": "The ARIA label for close button of mobile sidebar" }, "theme.docs.sidebar.toggleSidebarButtonAriaLabel": { - "message": "Toggle navigation bar", + "message": "탐색 바 전환", "description": "The ARIA label for hamburger menu button of mobile navigation" }, "theme.SearchPage.typesenseLabel": { - "message": "Search by Typesense", + "message": "Typesense로 검색", "description": "The ARIA label for Typesense mention" }, "theme.SearchModal.searchBox.resetButtonTitle": { - "message": "Clear the query", + "message": "검색어 지우기", "description": "The label and ARIA label for search box reset button" }, "theme.SearchModal.searchBox.cancelButtonText": { - "message": "Cancel", + "message": "취소", "description": "The label and ARIA label for search box cancel button" }, "theme.SearchModal.startScreen.recentSearchesTitle": { - "message": "Recent", + "message": "최근", "description": "The title for recent searches" }, "theme.SearchModal.startScreen.noRecentSearchesText": { - "message": "No recent searches", + "message": "최근 검색어 없음", "description": "The text when no recent searches" }, "theme.SearchModal.startScreen.saveRecentSearchButtonTitle": { - "message": "Save this search", + "message": "이 검색 저장", "description": "The label for save recent search button" }, "theme.SearchModal.startScreen.removeRecentSearchButtonTitle": { - "message": "Remove this search from history", + "message": "기록에서 이 검색 삭제", "description": "The label for remove recent search button" }, "theme.SearchModal.startScreen.favoriteSearchesTitle": { - "message": "Favorite", + "message": "즐겨찾기", "description": "The title for favorite searches" }, "theme.SearchModal.startScreen.removeFavoriteSearchButtonTitle": { - "message": "Remove this search from favorites", + "message": "즐겨찾기에서 이 검색 삭제", "description": "The label for remove favorite search button" }, "theme.SearchModal.errorScreen.titleText": { - "message": "Unable to fetch results", + "message": "결과를 불러올 수 없습니다", "description": "The title for error screen of search modal" }, "theme.SearchModal.errorScreen.helpText": { - "message": "You might want to check your network connection.", + "message": "네트워크 연결을 확인해 보세요.", "description": "The help text for error screen of search modal" }, "theme.SearchModal.footer.selectText": { - "message": "to select", + "message": "선택", "description": "The explanatory text of the action for the enter key" }, "theme.SearchModal.footer.selectKeyAriaLabel": { - "message": "Enter key", + "message": "Enter 키", "description": "The ARIA label for the Enter key button that makes the selection" }, "theme.SearchModal.footer.navigateText": { - "message": "to navigate", + "message": "탐색", "description": "The explanatory text of the action for the Arrow up and Arrow down key" }, "theme.SearchModal.footer.navigateUpKeyAriaLabel": { - "message": "Arrow up", + "message": "위쪽 화살표", "description": "The ARIA label for the Arrow up key button that makes the navigation" }, "theme.SearchModal.footer.navigateDownKeyAriaLabel": { - "message": "Arrow down", + "message": "아래쪽 화살표", "description": "The ARIA label for the Arrow down key button that makes the navigation" }, "theme.SearchModal.footer.closeText": { - "message": "to close", + "message": "닫기", "description": "The explanatory text of the action for Escape key" }, "theme.SearchModal.footer.closeKeyAriaLabel": { - "message": "Escape key", + "message": "Esc 키", "description": "The ARIA label for the Escape key button that close the modal" }, "theme.SearchModal.footer.searchByText": { - "message": "Search by", + "message": "검색 제공:", "description": "The text explain that the search is making by Algolia" }, "theme.SearchModal.noResultsScreen.noResultsText": { - "message": "No results for", + "message": "검색 결과 없음", "description": "The text explains that there are no results for the following search" }, "theme.SearchModal.noResultsScreen.suggestedQueryText": { - "message": "Try searching for", + "message": "검색해 보세요.", "description": "The text for the suggested query when no results are found for the following search" }, "theme.SearchModal.noResultsScreen.reportMissingResultsText": { - "message": "Believe this query should return results?", + "message": "이렇게 검색했을 때 결과가 나와야 한다고 생각하십니까?", "description": "The text for the question where the user thinks there are missing results" }, "theme.SearchModal.noResultsScreen.reportMissingResultsLinkText": { - "message": "Let us know.", + "message": "우리에게 알려주세요.", "description": "The text for the link to report missing results" }, "theme.SearchModal.placeholder": { - "message": "Search docs", + "message": "문서 검색", "description": "The placeholder of the input of the DocSearch pop-up modal" }, "theme.colorToggle.ariaLabel.mode.system": { - "message": "system mode", + "message": "시스템 모드", "description": "The name for the system color mode" }, "theme.admonition.warning": { - "message": "warning", + "message": "경고", "description": "The default label used for the Warning admonition (:::warning)" }, "theme.DocSidebarItem.expandCategoryAriaLabel": { - "message": "Expand sidebar category '{label}'", + "message": "사이드바 카테고리 '{label}' 펼치기", "description": "The ARIA label to expand the sidebar category" }, "theme.DocSidebarItem.collapseCategoryAriaLabel": { - "message": "Collapse sidebar category '{label}'", + "message": "사이드바 카테고리 '{label}' 접기", "description": "The ARIA label to collapse the sidebar category" }, "theme.IconExternalLink.ariaLabel": { - "message": "(opens in new tab)", + "message": "(새 탭에서 열기)", "description": "The ARIA label for the external link icon" }, "theme.navbar.mobileDropdown.collapseButton.expandAriaLabel": { - "message": "Expand the dropdown", + "message": "드롭다운 펼치기", "description": "The ARIA label of the button to expand the mobile dropdown navbar item" }, "theme.navbar.mobileDropdown.collapseButton.collapseAriaLabel": { - "message": "Collapse the dropdown", + "message": "드롭다운 접기", "description": "The ARIA label of the button to collapse the mobile dropdown navbar item" }, "theme.blog.author.pageTitle": { @@ -485,35 +485,35 @@ "description": "The title of the page for a blog author" }, "theme.blog.authorsList.pageTitle": { - "message": "Authors", + "message": "작성자", "description": "The title of the authors page" }, "theme.blog.authorsList.viewAll": { - "message": "View all authors", + "message": "모든 작성자 보기", "description": "The label of the link targeting the blog authors page" }, "theme.blog.author.noPosts": { - "message": "This author has not written any posts yet.", + "message": "이 작성자는 아직 게시물을 작성하지 않았습니다.", "description": "The text for authors with 0 blog post" }, "theme.contentVisibility.unlistedBanner.title": { - "message": "Unlisted page", + "message": "목록에 없는 페이지", "description": "The unlisted content banner title" }, "theme.contentVisibility.unlistedBanner.message": { - "message": "This page is unlisted. Search engines will not index it, and only users having a direct link can access it.", + "message": "이 페이지는 목록에 없습니다. 검색 엔진은 이 페이지를 색인하지 않으며, 직접 링크가 있는 사용자만 접근할 수 있습니다.", "description": "The unlisted content banner message" }, "theme.contentVisibility.draftBanner.title": { - "message": "Draft page", + "message": "초안 페이지", "description": "The draft content banner title" }, "theme.contentVisibility.draftBanner.message": { - "message": "This page is a draft. It will only be visible in dev and be excluded from the production build.", + "message": "이 페이지는 초안입니다. 개발 환경에서만 표시되며 프로덕션 빌드에서는 제외됩니다.", "description": "The draft content banner message" }, "theme.docs.DocCard.categoryDescription.plurals": { - "message": "1 item|{count} items", + "message": "{count}개 항목", "description": "The default description for a category card in the generated index about how many items this category includes" } } diff --git a/i18n/ko/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/ko/docusaurus-plugin-content-docs/current/general/dns-providers.md index 4a2f98e8f..e0e7a78ab 100644 --- a/i18n/ko/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/ko/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### 필터링 하지 않음 - -| 프로토콜 | 주소 | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| 프로토콜 | 주소 | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Ad + malware blocking - -| 프로토콜 | 주소 | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Ad + malware + social media blocking - -| 프로토콜 | 주소 | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Ad + malware + adult + gambling blocking - -| 프로토콜 | 주소 | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Ad + malware + adult + gambling + social media blocking - -| 프로토콜 | 주소 | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### Unsecured -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | 프로토콜 | 주소 | | | -------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md b/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md index 76946d5ef..b531cd506 100644 --- a/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md +++ b/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md @@ -9,7 +9,7 @@ sidebar_position: 4 이는 무단 사용자가 접근하는 것을 방지하고 보안을 강화하는 데 도움이 됩니다. 추가적으로, 특정 프로필에 대해 다른 프로토콜의 사용을 제한할 수 있습니다. 이 기능은 당신의 DNS 서버 주소가 다른 사람에게 알려져 있을 때 특히 유용합니다. 비밀번호를 추가함으로써 접근을 차단하고 오직 당신만 사용할 수 있도록 할 수 있습니다. -## 설정 방법 +## How to set it up :::note 호환성 diff --git a/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md b/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md index 611240b57..d03175e45 100644 --- a/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md +++ b/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md @@ -7,7 +7,7 @@ sidebar_position: 3 차단된 요청은 쿼리 로그에 표시되지 않으며 총 한도에 포함되지 않습니다. -## 설정 방법 +## How to set it up ### 허용된 클라이언트 diff --git a/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index 8c44b5f93..e9b22a91a 100644 --- a/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,48 +3,58 @@ title: 자녀 보호 sidebar_position: 5 --- -## 자녀 보호 기능이란 무엇인가요? +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. -Parental control is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. +## How to set it up -## 설정 방법 +You can flexibly configure all features on your servers, including the parental control feature. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. -서버에서 자녀 보호 기능을 포함한 모든 기능을 유연하게 구성할 수 있습니다. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. +Then, go to the settings of the selected server and enable the required configurations. -그런 다음, 선택한 서버의 설정으로 이동하여 필요한 구성을 활성화하세요. +### Block adult websites -### 성인 웹사이트 차단 +Blocks websites with inappropriate and adult content. -부적절하고 성인용 콘텐츠가 포함된 웹사이트를 차단합니다. +![Blocked website \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) -![차단된 웹사이트 \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) +### Safe search -### 세이프서치 +Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave 및 Ecosia에서 불법적인 결과를 삭제합니다. +### YouTube restricted mode -![세이프서치 \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) +Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -### YouTube 제한 모드 +### Blocked services and websites -YouTube에서 영상에 대한 댓글을 보고 게시하며 18세 이상 콘텐츠와 상호작용할 수 있는 옵션을 삭제합니다. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. -![제한 모드 \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) +![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) -### 차단된 서비스 및 웹사이트 +### Block websites by category -AdGuard DNS는 원클릭으로 인기 서비스에 대한 액세스를 차단합니다. It’s useful if you don’t want connected devices to visit Instagram and YouTube, for example. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. -![차단된 서비스 \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) -### Block websites by category +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. -This feature lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### 일정 설정 +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -특정 날짜에 설정된 시간 간격으로 자녀 보호를 활성화합니다. 예를 들어, 자녀가 평일 23시까지만 YouTube 동영상을 시청하도록 허용했을 수 있습니다. 하지만 주말에는 이 접근이 제한되지 않습니다. 일정을 원하는 대로 사용자 맞춤화하고 원하는 시간 동안 선택한 사이트에 대한 접근을 차단하세요. +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![일정 \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index 184505b6c..aee21824d 100644 --- a/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ sidebar_position: 4 - **CDN**: 최종 사용자에게 콘텐츠를 빠르게 전송하는 전 세계 프록시 서버 네트워크인 CDN(콘텐츠 전송 네트워크)에 연결된 요청 - **기타** -### 상위 기업 +## 상위 기업 이 표에서는 가장 많이 방문된 또는 가장 많이 차단된 기업의 이름뿐만 아니라, 어떤 도메인에서 요청이 발생하는지 또는 어떤 도메인이 가장 많이 차단되고 있는지에 대한 정보도 제공합니다. diff --git a/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..b7ecaae8b --- /dev/null +++ b/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | 필수 | 설명 | Example | +| :---------------- | :------------ | :-- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | 정수 | 아니오 | Detected account ID, if any. | `1234` | +| `DnsServerId` | 문자열 | 아니오 | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | 문자열 | 아니오 | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | 문자열 | 아니오 | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | 문자열 | 아니오 | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | 문자열 | 네 | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | 문자열 | 아니오 | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | 문자열 | 아니오 | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | 정수 | 네 | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | 정수 | 아니오 | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | 정수 | 네 | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | 정수 | 네 | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | 정수 | 네 | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | 정수 | 네 | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | 정수 | 네 | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | 정수 | 네 | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | 정수 | 네 | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | 문자열 | 아니오 | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | 네 | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | 네 | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## FAQ + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index c6b79e21e..d4391e649 100644 --- a/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: 쿼리 로그 sidebar_position: 5 --- -## 쿼리 로그란 무엇인가요? +## What is Query log? -쿼리 로그는 AdGuard DNS를 사용하기 위한 유용한 도구입니다. +_Query log_ is a useful tool for working with AdGuard DNS. 선택한 기간 동안 기기에서 만든 모든 요청을 보고 요청을 상태, 유형, 기업, 기기, 국가별로 정렬할 수 있습니다. ## 사용 방법 -Here’s what you can see and what you can do in the _Query log_. +Here’s what you can see and what you can do in _Query log_. ### 요청에 대한 자세한 정보 -![요청 유형 \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### 도메인 차단 및 차단 해제 사용 가능한 도구를 사용하여 로그를 남기지 않고 요청을 차단하거나 차단을 해제할 수 있습니다. -![차단 해제 도메인 \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### 요청 정렬 diff --git a/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index e6b7a7954..7efc3fcdd 100644 --- a/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/ko/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS는 쿼리를 모니터링하기 위한 다양한 유용한 도구를 - [트래픽 목적지](/private-dns/statistics-and-log/traffic-destination.md) - [기업](/private-dns/statistics-and-log/companies.md) - [쿼리 로그](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/nl/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/nl/docusaurus-plugin-content-docs/current/general/dns-providers.md index 1f37742b4..0cfa339c4 100644 --- a/i18n/nl/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/nl/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### Niet-filterend - -| Protocol | Adres | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| Protocol | Adres | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Ad + malware blocking - -| Protocol | Adres | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Ad + malware + social media blocking - -| Protocol | Adres | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Ad + malware + adult + gambling blocking - -| Protocol | Adres | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Ad + malware + adult + gambling + social media blocking - -| Protocol | Adres | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Reguliere DNS-servers die bescherming bieden tegen phishing en spyware. Ze omvat #### Onbeveiligd -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protocol | Adres | | | -------------- | --------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index 01e70cbdf..143c85ffa 100644 --- a/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,9 +3,7 @@ title: Parental control sidebar_position: 5 --- -## What is it - -Parental control is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. ## How to set it up @@ -23,28 +21,40 @@ Blocks websites with inappropriate and adult content. Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -![Safe search \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) - ### YouTube restricted mode Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -![Restricted mode \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) - ### Blocked services and websites -AdGuard DNS blocks access to popular services with one click. It’s useful if you don’t want connected devices to visit Instagram and YouTube, for example. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. ![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) -### Websites blokkeren per categorie +### Block websites by category + +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. + +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) + +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. -Met deze functie kun je de toegang beperken tot specifieke categorieën websites door te kiezen uit meer dan 20 categorieën, waaronder _Volwassen content_, _Games_, _Banken_ en _Communicatie_. Als je bijvoorbeeld sites blokkeert die informatie bevatten over alcohol, tabak of drugs, kan het geselecteerde apparaat geen pagina's meer openen die onder die categorieën vallen. +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Categoriegebaseerde blokkering \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### Schedule off time +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -Enables parental controls on selected days with a specified time interval. Je hebt je kind bijvoorbeeld toegestaan om doordeweeks slechts tot 23:00 YouTube-video's te bekijken. But on weekends, this access is not restricted. Customize the schedule to your liking and block access to selected sites during the hours you want. +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![Schedule \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index b21375a03..1e626b858 100644 --- a/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ These are further divided into sub-categories: - **CDN**: request connected to Content Delivery Network (CDN), a worldwide network of proxy servers that speeds the delivery of content to end users - **Other** -### Top companies +## Top companies In this table, we not only show the names of the most visited or most blocked companies, but also display information about which domains are being requested from or which domains are being blocked the most. diff --git a/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..9076e8cfd --- /dev/null +++ b/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Required | Description | Example | +| :---------------- | :------------ | :------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | No | Detected account ID, if any. | `1234` | +| `DnsServerId` | string | No | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | string | No | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | string | No | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | string | No | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | string | Yes | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | string | No | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | string | No | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Yes | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | No | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Yes | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Yes | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Yes | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Yes | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Yes | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Yes | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Yes | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | string | No | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Yes | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Yes | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## Veelgestelde vragen + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 90ecc6874..3367affbe 100644 --- a/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Query log sidebar_position: 5 --- -## What is Query log +## What is Query log? -Query log is a useful tool for working with AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. It allows you to view all requests made by your devices during the selected time period and sort requests by status, type, company, device, country. ## How to use it -Here’s what you can see and what you can do in the _Query log_. +Here’s what you can see and what you can do in _Query log_. ### Detailed information on requests -![Requests info \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Blocking and unblocking domains Requests can be blocked and unblocked without leaving the log, using the available tools. -![Unblock domain \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Sorting requests diff --git a/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index e4cb44a7a..260153110 100644 --- a/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/nl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS provides a wide range of useful tools for monitoring queries: - [Traffic destination](/private-dns/statistics-and-log/traffic-destination.md) - [Companies](/private-dns/statistics-and-log/companies.md) - [Query log](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/pt-BR/code.json b/i18n/pt-BR/code.json index 32ae381fb..89cf8079f 100644 --- a/i18n/pt-BR/code.json +++ b/i18n/pt-BR/code.json @@ -8,11 +8,11 @@ "description": "The site tagline used in meta description" }, "apiChangelog.loading": { - "message": "Loading changelog…", + "message": "Carregando changelog…", "description": "Placeholder shown while the API changelog is being loaded" }, "apiChangelog.error": { - "message": "Failed to load the changelog. You can view the original at {link}.", + "message": "Falha ao carregar o changelog. Você pode visualizar o original em {link}.", "description": "Error message shown when the API changelog cannot be loaded. {link} is a link to the original changelog on adguard-dns.io" }, "apiChangelog.versions": { @@ -20,7 +20,7 @@ "description": "Accessible name of the version list sidebar on the API changelog page" }, "apiReference.loading": { - "message": "Loading API reference…", + "message": "Carregando a referência da API…", "description": "Placeholder shown while the API reference (Swagger UI) is being loaded" }, "theme.NotFound.title": { @@ -297,7 +297,7 @@ "description": "The search page title for empty query" }, "theme.SearchPage.documentsFound.plurals": { - "message": "One document found|{count} documents found", + "message": "1 documento encontrado|{count} documentos encontrados", "description": "Pluralized label for \"{count} documents found\". Use as much plural forms (separated by \"|\") as your language support (see https://www.unicode.org/cldr/cldr-aux/charts/34/supplemental/language_plural_rules.html)" }, "theme.SearchPage.noResultsText": { @@ -321,15 +321,15 @@ "description": "The paragraph for fetching new search results" }, "theme.admonition.note": { - "message": "note", + "message": "nota", "description": "The default label used for the Note admonition (:::note)" }, "theme.admonition.tip": { - "message": "tip", + "message": "dica", "description": "The default label used for the Tip admonition (:::tip)" }, "theme.admonition.danger": { - "message": "danger", + "message": "perigo", "description": "The default label used for the Danger admonition (:::danger)" }, "theme.admonition.info": { @@ -337,7 +337,7 @@ "description": "The default label used for the Info admonition (:::info)" }, "theme.admonition.caution": { - "message": "caution", + "message": "cuidado", "description": "The default label used for the Caution admonition (:::caution)" }, "theme.NavBar.navAriaLabel": { @@ -345,15 +345,15 @@ "description": "The ARIA label for the main navigation" }, "theme.docs.sidebar.navAriaLabel": { - "message": "Docs sidebar", + "message": "Barra lateral do Documentos", "description": "The ARIA label for the sidebar navigation" }, "theme.docs.sidebar.closeSidebarButtonAriaLabel": { - "message": "Close navigation bar", + "message": "Fechar barra de navegação", "description": "The ARIA label for close button of mobile sidebar" }, "theme.docs.sidebar.toggleSidebarButtonAriaLabel": { - "message": "Toggle navigation bar", + "message": "Alternar barra de navegação", "description": "The ARIA label for hamburger menu button of mobile navigation" }, "theme.SearchPage.typesenseLabel": { @@ -373,7 +373,7 @@ "description": "The title for recent searches" }, "theme.SearchModal.startScreen.noRecentSearchesText": { - "message": "No recent searches", + "message": "Nenhuma pesquisa recente", "description": "The text when no recent searches" }, "theme.SearchModal.startScreen.saveRecentSearchButtonTitle": { @@ -389,43 +389,43 @@ "description": "The title for favorite searches" }, "theme.SearchModal.startScreen.removeFavoriteSearchButtonTitle": { - "message": "Remove this search from favorites", + "message": "Remover esta pesquisa dos favoritos", "description": "The label for remove favorite search button" }, "theme.SearchModal.errorScreen.titleText": { - "message": "Unable to fetch results", + "message": "Não foi possível buscar resultados", "description": "The title for error screen of search modal" }, "theme.SearchModal.errorScreen.helpText": { - "message": "You might want to check your network connection.", + "message": "Talvez seja necessário verificar sua conexão de rede.", "description": "The help text for error screen of search modal" }, "theme.SearchModal.footer.selectText": { - "message": "to select", + "message": "para selecionar", "description": "The explanatory text of the action for the enter key" }, "theme.SearchModal.footer.selectKeyAriaLabel": { - "message": "Enter key", + "message": "Digite a chave de licença", "description": "The ARIA label for the Enter key button that makes the selection" }, "theme.SearchModal.footer.navigateText": { - "message": "to navigate", + "message": "para navegar", "description": "The explanatory text of the action for the Arrow up and Arrow down key" }, "theme.SearchModal.footer.navigateUpKeyAriaLabel": { - "message": "Arrow up", + "message": "Seta para cima", "description": "The ARIA label for the Arrow up key button that makes the navigation" }, "theme.SearchModal.footer.navigateDownKeyAriaLabel": { - "message": "Arrow down", + "message": "Seta para baixo", "description": "The ARIA label for the Arrow down key button that makes the navigation" }, "theme.SearchModal.footer.closeText": { - "message": "to close", + "message": "para fechar", "description": "The explanatory text of the action for Escape key" }, "theme.SearchModal.footer.closeKeyAriaLabel": { - "message": "Escape key", + "message": "Tecla Esc", "description": "The ARIA label for the Escape key button that close the modal" }, "theme.SearchModal.footer.searchByText": { @@ -445,7 +445,7 @@ "description": "The text for the question where the user thinks there are missing results" }, "theme.SearchModal.noResultsScreen.reportMissingResultsLinkText": { - "message": "Let us know.", + "message": "Informe-nos.", "description": "The text for the link to report missing results" }, "theme.SearchModal.placeholder": { @@ -453,31 +453,31 @@ "description": "The placeholder of the input of the DocSearch pop-up modal" }, "theme.colorToggle.ariaLabel.mode.system": { - "message": "system mode", + "message": "modo do sistema", "description": "The name for the system color mode" }, "theme.admonition.warning": { - "message": "warning", + "message": "aviso", "description": "The default label used for the Warning admonition (:::warning)" }, "theme.DocSidebarItem.expandCategoryAriaLabel": { - "message": "Expand sidebar category '{label}'", + "message": "Expandir a categoria da barra lateral '{label}'", "description": "The ARIA label to expand the sidebar category" }, "theme.DocSidebarItem.collapseCategoryAriaLabel": { - "message": "Collapse sidebar category '{label}'", + "message": "Recolher a categoria da barra lateral '{label}'", "description": "The ARIA label to collapse the sidebar category" }, "theme.IconExternalLink.ariaLabel": { - "message": "(opens in new tab)", + "message": "(abre em uma nova guia)", "description": "The ARIA label for the external link icon" }, "theme.navbar.mobileDropdown.collapseButton.expandAriaLabel": { - "message": "Expand the dropdown", + "message": "Expandir o menu suspenso", "description": "The ARIA label of the button to expand the mobile dropdown navbar item" }, "theme.navbar.mobileDropdown.collapseButton.collapseAriaLabel": { - "message": "Collapse the dropdown", + "message": "Recolher o menu suspenso", "description": "The ARIA label of the button to collapse the mobile dropdown navbar item" }, "theme.blog.author.pageTitle": { @@ -485,35 +485,35 @@ "description": "The title of the page for a blog author" }, "theme.blog.authorsList.pageTitle": { - "message": "Authors", + "message": "Autores", "description": "The title of the authors page" }, "theme.blog.authorsList.viewAll": { - "message": "View all authors", + "message": "Ver todos os autores", "description": "The label of the link targeting the blog authors page" }, "theme.blog.author.noPosts": { - "message": "This author has not written any posts yet.", + "message": "Este autor ainda não escreveu nenhuma publicação.", "description": "The text for authors with 0 blog post" }, "theme.contentVisibility.unlistedBanner.title": { - "message": "Unlisted page", + "message": "Página não listada", "description": "The unlisted content banner title" }, "theme.contentVisibility.unlistedBanner.message": { - "message": "This page is unlisted. Search engines will not index it, and only users having a direct link can access it.", + "message": "Esta página não está listada. Os mecanismos de pesquisa não a indexarão, e somente usuários que tiverem um link direto poderão acessá-la.", "description": "The unlisted content banner message" }, "theme.contentVisibility.draftBanner.title": { - "message": "Draft page", + "message": "Página de rascunho", "description": "The draft content banner title" }, "theme.contentVisibility.draftBanner.message": { - "message": "This page is a draft. It will only be visible in dev and be excluded from the production build.", + "message": "Esta página é um rascunho. Ela ficará visível apenas no ambiente de desenvolvimento e será excluída da compilação de produção.", "description": "The draft content banner message" }, "theme.docs.DocCard.categoryDescription.plurals": { - "message": "1 item|{count} items", + "message": "1 item|{count} itens", "description": "The default description for a category card in the generated index about how many items this category includes" } } diff --git a/i18n/pt-BR/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/pt-BR/docusaurus-plugin-content-docs/current/general/dns-providers.md index 73de6c34d..b7a5c4c2f 100644 --- a/i18n/pt-BR/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/pt-BR/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-sobre-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-sobre-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) fornece DNS publicamente acessível com minimização de QNAME, terminais localizados na Alemanha, Cingapura, Suécia, Reino Unido e Estados Unidos (Dallas e Nova York). - -#### Sem filtragem - -| Protocolo | Endereço | | -| --------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-sobre-HTTPS | `https://dns.mullvad.net/dns-query` | [Adicionar ao AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Adicionar ao AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-sobre-TLS | `tls://dns.mullvad.net` | [Adicionar ao AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Adicionar ao AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| Protocolo | Endereço | | -| --------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-sobre-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Adicionar ao AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Adicionar ao AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-sobre-TLS | `tls://adblock.dns.mullvad.net` | [Adicionar ao AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Adicionar ao AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Ad + malware blocking - -| Protocolo | Endereço | | -| --------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-sobre-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Adicionar ao AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Adicionar ao AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-sobre-TLS | `tls://base.dns.mullvad.net` | [Adicionar ao AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Adicionar ao AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Bloqueio de anúncios + malware + redes sociais - -| Protocolo | Endereço | | -| --------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-sobre-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Adicionar ao AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Adicionar ao AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-sobre-TLS | `tls://extended.dns.mullvad.net` | [Adicionar ao AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Adicionar ao AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Bloqueio de anúncios + malware + adulto + jogos de azar - -| Protocolo | Endereço | | -| --------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-sobre-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Adicionar ao AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Adicionar ao AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-sobre-TLS | `tls://family.dns.mullvad.net` | [Adicionar ao AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Adicionar ao AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Bloqueio de anúncios + malware + adulto + jogos de azar + redes sociais - -| Protocolo | Endereço | | -| --------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-sobre-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-sobre-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Servidores DNS regulares que fornecem proteção contra phishing e spyware. Eles #### Inseguro -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protocolo | Endereço | | | --------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md b/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md index f6737a975..4876fb131 100644 --- a/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md +++ b/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md @@ -9,7 +9,7 @@ DNS-over-HTTPS com autenticação permite que você defina um nome de usuário e Isso ajuda a prevenir que usuários não autorizados tenham acesso e melhora a segurança. Além disso, você pode restringir o uso de outros protocolos para perfis específicos. Esse recurso é particularmente útil quando o endereço do seu servidor DNS é conhecido por outros. Ao adicionar uma senha, você pode bloquear o acesso e garantir que apenas você possa usá-lo. -## Como configurar +## How to set it up :::note Compatibilidade diff --git a/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md b/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md index a8da09c6a..39795e1dd 100644 --- a/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md +++ b/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md @@ -7,7 +7,7 @@ Ao configurar as configurações de acesso, você pode proteger seu AdGuard DNS Solicitações bloqueadas não serão exibidas no registro de consulta e não são contadas no limite total. -## Como configurar +## How to set it up ### Clientes permitidos diff --git a/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index 11207cbec..6a175c1e9 100644 --- a/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,48 +3,58 @@ title: Controle parental sidebar_position: 5 --- -## Definição +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. -Parental control is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. +## How to set it up -## Como configurar +You can flexibly configure all features on your servers, including the parental control feature. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. -Você pode configurar todos os recursos de forma flexível em seus servidores, incluindo o recurso de controle parental. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. +Then, go to the settings of the selected server and enable the required configurations. -Em seguida, vá para as configurações do servidor selecionado e ative as configurações necessárias. +### Block adult websites -### Bloqueando sites adultos +Blocks websites with inappropriate and adult content. -Bloqueia sites com conteúdo impróprio e adulto. +![Blocked website \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) -![Site bloqueado \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) +### Safe search -### Pesquisa segura +Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -Remove resultados impróprios do Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave e Ecosia. +### YouTube restricted mode -![Pesquisa segura \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) +Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -### Modo restrito do YouTube +### Blocked services and websites -Remove a opção de visualizar e postar comentários em vídeos e interagir com conteúdo 18+ no YouTube. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. -![Modo restrito \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) +![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) -### Sites e serviços bloqueados +### Block websites by category -O AdGuard DNS bloqueia o acesso a serviços populares com um clique. It’s useful if you don’t want connected devices to visit Instagram and YouTube, for example. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. -![Serviços bloqueados \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) -### Block websites by category +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. -This feature lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### Agendamento de desativação +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -Ativa os controles parentais em dias selecionados com um intervalo de tempo especificado. Por exemplo, você pode ter permitido que seu filho assistisse a vídeos do YouTube apenas até às 23:00 nos dias de semana. Mas nos fins de semana, esse acesso não é restrito. Personalize o agendamento de acordo com sua preferência e bloqueie o acesso a sites selecionados durante as horas que você desejar. +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![Agendamento \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index ae64fb9b4..0c0e491d8 100644 --- a/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ Essas são ainda divididas em subcategorias: - **CDN**: solicitação conectada à Rede de Distribuição de Conteúdo (CDN), uma rede mundial de servidores proxy que acelera a entrega de conteúdo aos usuários finais - **Outro** -### Principais empresas +## Principais empresas Nesta tabela, não mostramos apenas os nomes das empresas mais visitadas ou mais bloqueadas, mas também exibimos informações sobre quais domínios estão sendo solicitados ou quais domínios estão sendo mais bloqueados. diff --git a/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..cf539aff6 --- /dev/null +++ b/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Obrigatório | Descrição | Example | +| :---------------- | :------------ | :---------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | Não | Detected account ID, if any. | `1234` | +| `DnsServerId` | linhas | Não | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | linhas | Não | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | linhas | Não | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | linhas | Não | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | linhas | Sim | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | linhas | Não | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | linhas | Não | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Sim | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | Não | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Sim | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Sim | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Sim | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Sim | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Sim | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Sim | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Sim | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | linhas | Não | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Sim | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Sim | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## FAQ + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index ee85f9fcd..80201e197 100644 --- a/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Registro de consultas sidebar_position: 5 --- -## O que é o Registro de consultas +## What is Query log? -O registro de consultas é uma ferramenta útil para trabalhar com AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. Ele permite que você veja todas as solicitações feitas pelos seus dispositivos durante o período de tempo selecionado e classifique as solicitações por status, tipo, empresa, dispositivo, país. ## Como usar -Here’s what you can see and what you can do in the _Query log_. +Here’s what you can see and what you can do in _Query log_. ### Informações detalhadas sobre as solicitações -![Informações sobre solicitações \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Bloqueando e desbloqueando domínios As solicitações podem ser bloqueadas e desbloqueadas sem sair do registro, utilizando as ferramentas disponíveis. -![Desbloquear domínio \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Classificação de solicitações diff --git a/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index 757bbb6ec..10a40d4d4 100644 --- a/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/pt-BR/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ O AdGuard DNS fornece um amplo alcance de ferramentas úteis para monitorar inqu - [Destino do tráfego](/private-dns/statistics-and-log/traffic-destination.md) - [Empresas](/private-dns/statistics-and-log/companies.md) - [Registro de inquérito](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/ru/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/ru/docusaurus-plugin-content-docs/current/general/dns-providers.md index 78b0fb22c..9d297ab0c 100644 --- a/i18n/ru/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/ru/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor — это бесплатный альтер | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Добавить в AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Добавить в AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Добавить в AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Добавить в AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) предоставляет общедоступный DNS-сервис с минимизацией QNAME, конечными точками в Германии, Сингапуре, Швеции, Великобритании и США (Даллас и Нью-Йорк). - -#### Нефильтрующий - -| Протокол | Адрес | | -| -------------- | ----------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Добавить в AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Добавить в AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Добавить в AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Добавить в AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Блокировка рекламы - -| Протокол | Адрес | | -| -------------- | ------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Добавить в AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Добавить в AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Добавить в AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Добавить в AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Блокировка рекламы и вредоносного ПО - -| Протокол | Адрес | | -| -------------- | ---------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Добавить в AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Добавить в AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Добавить в AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Добавить в AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Блокировка рекламы, вредоносного ПО и кнопок социальных сетей - -| Протокол | Адрес | | -| -------------- | -------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Добавить в AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Добавить в AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Добавить в AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Добавить в AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Блокировка рекламы, вредоносного ПО, взрослых и азартных игр - -| Протокол | Адрес | | -| -------------- | ------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Добавить в AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Добавить в AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Добавить в AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Добавить в AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Блокировка рекламы, вредоносного ПО, взрослых и азартных игр, а также кнопок социальных сетей - -| Протокол | Адрес | | -| -------------- | --------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Добавить в AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Добавить в AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Добавить в AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Добавить в AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Hurricane Electric Public Recursor — это бесплатный альтер #### Незащищённый -У незащищённых DNS-серверов нет списков блокировки, DNSSEC или EDNS Сlient Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Протокол | Адрес | | | -------------- | ------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md b/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md index ad4a95293..95ec4e852 100644 --- a/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md +++ b/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md @@ -9,7 +9,7 @@ DNS-over-HTTPS с аутентификацией позволяет задать Это помогает предотвратить несанкционированный доступ и повысить безопасность. Кроме того, можно ограничить использование других протоколов для конкретных профилей. Эта функция особенно полезна, если адрес вашего DNS-сервера известен другим. Добавив пароль, вы можете заблокировать доступ и убедиться, что только вы можете его использовать. -## Как настроить +## How to set it up :::note Совместимость diff --git a/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md b/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md index b13d43222..c0918a5bf 100644 --- a/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md +++ b/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md @@ -7,7 +7,7 @@ sidebar_position: 3 Заблокированные запросы не будут отображаться в журнале запросов и не учитываются в общем лимите. -## Как настроить +## How to set it up ### Разрешённые клиенты diff --git a/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index bbf3a0430..d533435d6 100644 --- a/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,48 +3,58 @@ title: Родительский контроль sidebar_position: 5 --- -## Что это такое +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. -Родительский контроль — это набор настроек, который позволяет гибко настраивать доступ к определённым сайтам с «чувствительным» контентом. С помощью этой функции можно ограничить доступ детей к сайтам для взрослых, настроить поисковые запросы, заблокировать использование популярных сервисов и многое другое. +## How to set it up -## Как настроить +You can flexibly configure all features on your servers, including the parental control feature. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. -Вы можете гибко настроить все функции на своих серверах, включая функцию родительского контроля. [В соответствующей статье](private-dns/server-and-settings/server-and-settings.md) вы можете ознакомиться с тем, что такое «сервер» в AdGuard DNS, и узнать, как создать разные серверы с разными наборами настроек. +Then, go to the settings of the selected server and enable the required configurations. -Затем перейдите в настройки выбранного сервера и включите необходимые конфигурации. +### Block adult websites -### Блокировать сайты для взрослых +Blocks websites with inappropriate and adult content. -Блокирует сайты с неподобающим и контентом для взрослых. +![Blocked website \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) -![Заблокированный сайт \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) +### Safe search -### Безопасный поиск +Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -Удаляет неподобающие результаты из Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave и Ecosia. +### YouTube restricted mode -![Безопасный поиск \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) +Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -### Режим ограниченной работы YouTube +### Blocked services and websites -Удаляет возможность просматривать и оставлять комментарии под видео и взаимодействовать с контентом 18+ на YouTube. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. -![Режим ограниченной работы \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) +![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) -### Заблокированные сервисы и сайты +### Block websites by category -AdGuard DNS блокирует доступ к популярным сервисам одним нажатием. Это полезно, если вы не хотите, чтобы подключённые устройства заходили, например, на YouTube или в Instagram. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. -![Заблокированные сервисы \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) -### Block websites by category +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. -This feature lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### Настроить расписание +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -Включает Родительский контроль в выбранные дни с указанным интервалом времени. Например, вы можете разрешить ребёнку смотреть видео на YouTube только до 23:00 в будние дни. Но в выходные этот доступ не ограничен. Настройте расписание по вашему усмотрению и блокируйте доступ к выбранным сайтам в нужное вам время. +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![Расписание \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index e5b721ad5..bd66c56ff 100644 --- a/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ sidebar_position: 4 - **CDN**: запросы, связанные с Content Delivery Network (CDN), глобальной сетью прокси-серверов, ускоряющей доставку контента конечным пользователям - **Прочее** -### Топ компаний +## Топ компаний В этой таблице мы показываем не только названия самых посещаемых или блокируемых компаний, но и информацию о том, с каких доменов запрашиваются данные или какие домены блокируются чаще всего. diff --git a/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..2406ba822 --- /dev/null +++ b/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Обязательно | Описание | Example | +| :---------------- | :------------ | :---------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | Нет | Detected account ID, if any. | `1234` | +| `DnsServerId` | string | Нет | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | string | Нет | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | string | Нет | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | string | Нет | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | string | Да | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | string | Нет | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | string | Нет | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Да | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | Нет | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Да | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Да | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Да | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Да | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Да | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Да | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Да | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | string | Нет | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Да | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Да | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## FAQ + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 8ced4206e..83bc2db26 100644 --- a/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Журнал запросов sidebar_position: 5 --- -## Что такое журнал запросов +## What is Query log? -Журнал запросов — полезный инструмент для работы с AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. Он позволяет вам просматривать все запросы, сделанные вашими устройствами за выбранный период времени, и сортировать запросы по статусу, типу, компании, устройству, стране. ## Как им пользоваться -Вот что вы можете увидеть и что вы можете сделать в _Журнале запросов_. +Here’s what you can see and what you can do in _Query log_. ### Подробная информация о запросах -![Requests info \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Блокировка и разблокировка доменов Запросы могут быть заблокированы и разблокированы без выхода из журнала, с использованием доступных инструментов. -![Unblock domain \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Сортировка запросов diff --git a/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index 506c6905c..06ff9e231 100644 --- a/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/ru/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS предоставляет широкий диапазон поле - [Журнал запросов](/private-dns/statistics-and-log/traffic-destination.md) - [Компании](/private-dns/statistics-and-log/companies.md) - [Журнал запросов](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/sk/docusaurus-plugin-content-docs/current/general/dns-providers.md index 614bfba98..15348bd48 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### Non-filtering - -| Protocol | Address | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| Protocol | Address | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Ad + malware blocking - -| Protocol | Address | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Ad + malware + social media blocking - -| Protocol | Address | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Ad + malware + adult + gambling blocking - -| Protocol | Address | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Ad + malware + adult + gambling + social media blocking - -| Protocol | Address | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### Unsecured -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protocol | Address | | | -------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/nintendo-switch.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/nintendo-switch.md index 34a96f55a..0059e101c 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/nintendo-switch.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/nintendo-switch.md @@ -19,8 +19,8 @@ Configure your game console to use a public AdGuard DNS server or configure it v 4. Click _Change Settings_ for the selected Wi-Fi network. 5. Scroll down and select _DNS Settings_. 6. In the _DNS Server_ field, enter one of the following DNS server addresses: - - `94.140.14.49` - - `94.140.14.59` + - `94.140.14.49` + - `94.140.14.59` 7. Save your DNS settings. It would be preferable to use linked IP (or dedicated IP if you have a Team subscription): diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/nintendo.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/nintendo.md index 350a20ce7..ea70fac91 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/nintendo.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/nintendo.md @@ -26,8 +26,8 @@ Configure your game console to use a public AdGuard DNS server or configure it v 5. Set _Automatic_ to _Manual_. 6. Select _Primary DNS_. Hold down the left arrow (B button) to delete the existing DNS. 7. In the _Primary DNS_ field, enter one of the following DNS server addresses: - - `94.140.14.49` - - `94.140.14.59` + - `94.140.14.49` + - `94.140.14.59` 8. Save the settings. It would be preferable to use linked IP (or dedicated IP if you have a Team subscription): diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/playstation.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/playstation.md index ed6b36bb8..766f7d3b9 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/playstation.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/playstation.md @@ -24,8 +24,8 @@ Configure your game console to use a public AdGuard DNS server or configure it v 7. For _DHCP Host Name_, select _Do Not Specify_. 8. For _DNS Settings_, select _Manual_. 9. In the _DNS Server_ field, enter one of the following DNS server addresses: - - `94.140.14.49` - - `94.140.14.59` + - `94.140.14.49` + - `94.140.14.59` 10. Select _Next_ to continue. 11. On the _MTU Settings_ screen, select _Automatic_. 12. On the _Proxy Server_ screen, select _Do Not Use_. @@ -43,8 +43,8 @@ Configure your game console to use a public AdGuard DNS server or configure it v 7. For _DHCP Host Name_, select _Do Not Specify_. 8. For _DNS Settings_, select _Manual_. 9. In the _DNS Server_ field, enter one of the following DNS server addresses: - - `94.140.14.49` - - `94.140.14.59` + - `94.140.14.49` + - `94.140.14.59` 10. Select _Next_ to continue. 11. On the _MTU Settings_ screen, select _Automatic_. 12. On the _Proxy Server_ screen, select _Do Not Use_. diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/steam.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/steam.md index 9f46e6bec..5f2dc0f30 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/steam.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/steam.md @@ -19,8 +19,8 @@ Configure your game console to use a public AdGuard DNS server or configure it v 4. Select IPv4 or IPv6, depending on the type of network you’re using. 5. Select _Automatic (DHCP) addresses only_ or _Automatic (DHCP)_. 6. In the _DNS Server_ field, enter one of the following DNS server addresses: - - `94.140.14.49` - - `94.140.14.59` + - `94.140.14.49` + - `94.140.14.59` 7. Save the changes. It would be preferable to use linked IP (or dedicated IP if you have a Team subscription): diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/xbox-one.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/xbox-one.md index 6f611ccfa..77975df23 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/xbox-one.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/game-consoles/xbox-one.md @@ -19,8 +19,8 @@ Configure your game console to use a public AdGuard DNS server or configure it v 4. Under _Network Settings_, select _Advanced Settings_. 5. Under _DNS Settings_, select _Manual_. 6. In the _DNS Server_ field, enter one of the following DNS server addresses: - - `94.140.14.49` - - `94.140.14.59` + - `94.140.14.49` + - `94.140.14.59` 7. Save the changes. It would be preferable to use linked IP (or dedicated IP if you have a Team subscription): diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/mobile-and-desktop/macos.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/mobile-and-desktop/macos.md index 2da276b1f..ee2f70925 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/mobile-and-desktop/macos.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/mobile-and-desktop/macos.md @@ -8,7 +8,7 @@ To connect a macOS device to AdGuard DNS, first add it to _Dashboard_: 1. Go to _Dashboard_ and click _Connect new device_. 2. In the drop-down menu _Device type_, select Mac. 3. Name the device. - ![Connecting_device \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/choose_mac.png) + ![Connecting_device \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/choose_mac.png) ## Use AdGuard Ad Blocker (paid option) @@ -17,20 +17,20 @@ The AdGuard app lets you use encrypted DNS, making it perfect for setting up AdG 1. [Install the app](https://adguard.com/adguard-mac/overview.html) on the device you want to connect to AdGuard DNS. 2. Open the app. 3. Click the icon in the top right corner. - ![Protection icon \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step3.png) + ![Protection icon \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step3.png) 4. Select _Preferences..._. - ![Preferences \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step4.png) + ![Preferences \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step4.png) 5. Click the _DNS_ tab from the top row of icons. - ![DNS tab \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step5.png) + ![DNS tab \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step5.png) 6. Enable DNS protection by ticking the box at the top. - ![DNS protection \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step6.png) + ![DNS protection \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step6.png) 7. Click _+_ in the bottom left corner. - ![Click + \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step7.png) + ![Click + \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step7.png) 8. Copy one of the following DNS addresses and paste it into the _DNS servers_ field in the app. If you are not sure which one to prefer, select _DNS-over-HTTPS_. - ![DoH server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step8_1.png) - ![Create server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step8_2.png) + ![DoH server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step8_1.png) + ![Create server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step8_2.png) 9. Click _Save and Choose_. - ![Save and Choose \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step9.png) + ![Save and Choose \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step9.png) 10. Your newly created server should appear at the bottom of the list. ![Providers \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_ab/mac_step10.png) @@ -43,12 +43,12 @@ Not all VPN services support encrypted DNS. However, our VPN does, so if you nee 1. Install the [AdGuard VPN app](https://adguard-vpn.com/mac/overview.html) on the device you want to connect to AdGuard DNS. 2. Open the AdGuard VPN app. 3. Open _Settings_ → _App settings_ → _DNS servers_ → _Add Custom Server_. - ![Add custom server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_vpn/mac_step3.png) + ![Add custom server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_vpn/mac_step3.png) 4. Copy one of the following DNS addresses and paste it into the _DNS server addresses_ text field. If you are not sure which one to prefer, select DNS-over-HTTPS. - ![DNS servers \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_vpn/mac_step4.png) + ![DNS servers \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_vpn/mac_step4.png) 5. Click _Save and select_. 6. The DNS server you’ve added will appear at the bottom of the _Custom DNS servers_ list. - ![Custom DNS servers \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_vpn/mac_step6.png) + ![Custom DNS servers \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_vpn/mac_step6.png) All done! Your device is successfully connected to AdGuard DNS. @@ -64,11 +64,11 @@ If you are using a VPN, the configuration profile will be ignored. 1. On the device that you want to connect to AdGuard DNS, download the configuration profile. 2. Choose Apple menu → _System Settings_, click _Privacy & Security_ in the sidebar, then click _Profiles_ on the right (you may need to scroll down). - ![Profile Downloaded \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_profile/mac_step2.png) + ![Profile Downloaded \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_profile/mac_step2.png) 3. In the _Downloaded_ section, double-click the profile. - ![Downloaded \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_profile/mac_step3.png) + ![Downloaded \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_profile/mac_step3.png) 4. Review the profile contents and click _Install_. - ![Install \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_profile/mac_step4.png) + ![Install \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/mac_profile/mac_step4.png) 5. Enter the admin password and click _OK_. All done! Your device is successfully connected to AdGuard DNS. diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/mobile-and-desktop/windows.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/mobile-and-desktop/windows.md index 09f6ac895..6779fd9a3 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/mobile-and-desktop/windows.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/mobile-and-desktop/windows.md @@ -8,7 +8,7 @@ To connect a Windows device to AdGuard DNS, first add it to _Dashboard_: 1. Go to _Dashboard_ and click _Connect new device_. 2. In the drop-down menu _Device type_, select Windows. 3. Name the device. - ![Connecting_device \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/choose_windows.png) + ![Connecting_device \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/choose_windows.png) You can set it up via [AdGuard](#use-adguard-ad-blocker-paid-option) or [AdGuard VPN](#use-adguard-vpn) apps, in [Windows settings](#configure-via-windows-settings), or using the [AdGuard DNS Client](#use-adguard-dns-client). @@ -19,20 +19,20 @@ The AdGuard app lets you use encrypted DNS, making it perfect for setting up AdG 1. [Install the app](https://adguard.com/adguard-windows/overview.html) on the device you want to connect to AdGuard DNS. 2. Open the app. 3. Click _Settings_ at the top of the app’s home screen. - ![Settings \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step3.png) + ![Settings \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step3.png) 4. Select the _DNS Protection_ tab from the menu on the left. - ![DNS protection \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step4.png) + ![DNS protection \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step4.png) 5. Click your currently selected DNS server. - ![DNS server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step5.png) + ![DNS server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step5.png) 6. Scroll down and click _Add a custom DNS server_. - ![Add a custom DNS server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step6.png) + ![Add a custom DNS server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step6.png) 7. In the DNS upstreams field, paste one of the following addresses. If you’re not sure which one to prefer, choose DNS-over-HTTPS. - ![DoH server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step7_1.png) - ![Create server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step7_2.png) + ![DoH server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step7_1.png) + ![Create server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step7_2.png) 8. Click _Save and select_. - ![Save and select \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step8.png) + ![Save and select \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step8.png) 9. The DNS server you’ve added will appear at the bottom of the _Custom DNS servers_ list. - ![Custom DNS servers \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step9.png) + ![Custom DNS servers \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_step9.png) All done! Your device is successfully connected to AdGuard DNS. @@ -43,16 +43,16 @@ Not all VPN services support encrypted DNS. However, our VPN does, so if you nee 1. Install AdGuard VPN. 2. Open the app and click _Settings_. 3. Select _App settings_. - ![App settings \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_vpn/windows_step4.png) + ![App settings \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_vpn/windows_step4.png) 4. Scroll down and select _DNS servers_. - ![DNS servers \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_vpn/windows_step5.png) + ![DNS servers \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_vpn/windows_step5.png) 5. Click _Add custom DNS server_. - ![Add custom DNS server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_vpn/windows_step6.png) + ![Add custom DNS server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_vpn/windows_step6.png) 6. In the _Server address_ field, paste one of the following addresses. If you’re not sure which one to prefer, select DNS-over-HTTPS. - ![DoH server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_vpn/windows_step7_1.png) - ![Create server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_vpn/windows_step7_2.png) + ![DoH server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_vpn/windows_step7_1.png) + ![Create server \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_vpn/windows_step7_2.png) 7. Click _Save and select_. - ![Save and select \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_vpn/windows_step8.png) + ![Save and select \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_vpn/windows_step8.png) All done! Your device is successfully connected to AdGuard DNS. @@ -65,18 +65,18 @@ Available only on Windows 11. ::: 1. In the _Search_ bar on the taskbar, type **Ethernet settings** or **Wi-Fi settings**, depending on your connection type. - Click the network (Wi-Fi ID or Ethernet) you want to configure. - ![Search \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_settings_step_1.png) + Click the network (Wi-Fi ID or Ethernet) you want to configure. + ![Search \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_settings_step_1.png) 2. Scroll to _DNS server assignment_ and click _Edit_. - ![DNS server assignment \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_settings_step_2.png) + ![DNS server assignment \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_settings_step_2.png) 3. Change DNS settings to _Manual_. 4. Toggle the IPv4 switch to _On_. 5. Enter the following DNS server addresses: - - Preferred DNS: `94.140.14.49` - - Alternate DNS: `94.140.14.59` + - Preferred DNS: `94.140.14.49` + - Alternate DNS: `94.140.14.59` 6. Turn _DNS over HTTPS template_ to _On (manual template)_ and enter your personal DNS address. You can find it in the Dashboard under _Server settings_ → _Devices_ → _Devices settings_ → DNS-over-HTTPS. 7. Click _Save_. That’s it — your device is now connected to AdGuard DNS! - ![Save DNS settings \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_settings_done.png) + ![Save DNS settings \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/windows_ab/windows_settings_done.png) ## Use AdGuard DNS Client diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md index c203e14ff..cddac5d2c 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md @@ -23,6 +23,6 @@ This feature is supported by [AdGuard DNS Client](/dns-client/overview.md) as we 4. Configure DNS-over-HTTPS with authentication as you like. 5. Reconfigure your device to use this server in the AdGuard DNS Client or one of the AdGuard apps. 6. To do this, copy the address of the encrypted server and paste it into the AdGuard app or AdGuard DNS Client settings. - ![Copy address \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/doh_step6.png) + ![Copy address \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/doh_step6.png) 7. You can also deny the use of other protocols. - ![Deny protocols \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/deny_protocol.png) + ![Deny protocols \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/connect/deny_protocol.png) diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/asus.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/asus.md index 355a93893..58bec6b70 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/asus.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/asus.md @@ -19,7 +19,7 @@ If necessary: Configure DNS-over-TLS on ASUS, install the [ASUS Merlin firmware] 6. Change DNS Privacy Protocol to DNS-over-TLS (DoT). 7. Make sure the _DNS-over-TLS Profile_ is set to _Strict_. 8. Scroll down to the _DNS-over-TLS Servers List_ section. In the _Address_ field, enter one of the addresses below: - - `94.140.14.49` and `94.140.14.59` + - `94.140.14.49` and `94.140.14.59` 9. For _TLS Port_, enter 853. 10. In the _TLS Hostname_ field, enter the Private AdGuard DNS server address: - `{Your_Device_ID}.d.adguard-dns.com` @@ -33,9 +33,9 @@ If necessary: Configure DNS-over-TLS on ASUS, install the [ASUS Merlin firmware] 4. Select _WAN_ or _Internet_. 5. Open _DNS Settings_ or _DNS_. 6. Choose _Manual Setting_. Select _Use These DNS Servers_ or _Specify DNS Server Manually_ and enter the following DNS server addresses: - - IPv4: `94.140.14.49` and `94.140.14.59` - - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` + - IPv4: `94.140.14.49` and `94.140.14.59` + - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` 7. Save the settings. 8. Link your IP (or your dedicated IP if you have a Team subscription). - - [Dedicated IPs](/private-dns/connect-devices/other-options/dedicated-ip.md) - - [Linked IPs](/private-dns/connect-devices/other-options/linked-ip.md) + - [Dedicated IPs](/private-dns/connect-devices/other-options/dedicated-ip.md) + - [Linked IPs](/private-dns/connect-devices/other-options/linked-ip.md) diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/fritzbox.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/fritzbox.md index d672a8a63..2d92bcd77 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/fritzbox.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/fritzbox.md @@ -24,8 +24,8 @@ Use this guide if your FritzBox router does not support DNS-over-TLS configurati 3. Open _Internet_ or _Home Network_. 4. Select _DNS_ or _DNS Settings_. 5. Select _Manual DNS_, then _Use These DNS Servers_ or _Specify DNS Server Manually_, and enter the following DNS server addresses: - - IPv4: `94.140.14.49` and `94.140.14.59` - - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` + - IPv4: `94.140.14.49` and `94.140.14.59` + - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` 6. Save the settings. 7. Link your IP (or your dedicated IP if you have a Team subscription). diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/keenetic.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/keenetic.md index 10f12a749..dac9a5329 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/keenetic.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/keenetic.md @@ -39,8 +39,8 @@ Use these instructions if your Keenetic router does not support DNS-over-HTTPS o 4. Select _WAN_ or _Internet_. 5. Select _DNS_ or _DNS Settings_. 6. Choose _Manual DNS_. Select _Use These DNS Servers_ or _Specify DNS Server Manually_ and enter the following DNS server addresses: - - IPv4: `94.140.14.49` and `94.140.14.59` - - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` + - IPv4: `94.140.14.49` and `94.140.14.59` + - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` 7. Save the settings. 8. Link your IP (or your dedicated IP if you have a Team subscription). diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/mikrotik.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/mikrotik.md index 4a1cee66c..e497c347e 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/mikrotik.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/mikrotik.md @@ -8,57 +8,57 @@ MikroTik routers use the open-source RouterOS operating system, which provides r ## Configure DNS-over-HTTPS 1. Access your MikroTik router: - - Open your web browser and go to your router’s IP address (usually `192.168.88.1`) - - Alternatively, you can use Winbox to connect to your MikroTik router - - Enter your administrator username and password + - Open your web browser and go to your router’s IP address (usually `192.168.88.1`) + - Alternatively, you can use Winbox to connect to your MikroTik router + - Enter your administrator username and password 2. Import root certificate: - - Download the latest bundle of trusted root certificates: [https://curl.se/docs/caextract.html](https://curl.se/docs/caextract.html) - - Navigate to _Files_. Click _Upload_ and select the downloaded cacert.pem certificate bundle - - Go to _System_ → _Certificates_ → _Import_ - - In the _File Name_ field, choose the uploaded certificate file - - Click _Import_ + - Download the latest bundle of trusted root certificates: [https://curl.se/docs/caextract.html](https://curl.se/docs/caextract.html) + - Navigate to _Files_. Click _Upload_ and select the downloaded cacert.pem certificate bundle + - Go to _System_ → _Certificates_ → _Import_ + - In the _File Name_ field, choose the uploaded certificate file + - Click _Import_ 3. Configure DNS-over-HTTPS: - - Go to _IP_ → _DNS_ - - In the _Servers_ section, add the following AdGuard DNS servers: - - `94.140.14.49` - - `94.140.14.59` - - Set _Allow Remote Requests_ to _Yes_ (this is crucial for DoH to function) - - In the _Use DoH server_ field, enter the URL of the Private AdGuard DNS server: `https://d.adguard-dns.com/dns-query/*******` - - Click _OK_ + - Go to _IP_ → _DNS_ + - In the _Servers_ section, add the following AdGuard DNS servers: + - `94.140.14.49` + - `94.140.14.59` + - Set _Allow Remote Requests_ to _Yes_ (this is crucial for DoH to function) + - In the _Use DoH server_ field, enter the URL of the Private AdGuard DNS server: `https://d.adguard-dns.com/dns-query/*******` + - Click _OK_ 4. Create Static DNS Records: - - In the _DNS Settings_, click _Static_ - - Click _Add New_ - - Set _Name_ to `d.adguard-dns.com` - - Set _Type_ to `A` - - Set _Address_ to `94.140.14.49` - - Set _TTL_ to `1d 00:00:00` - - Repeat the process to create an identical entry, but with _Address_ set to `94.140.14.59` + - In the _DNS Settings_, click _Static_ + - Click _Add New_ + - Set _Name_ to `d.adguard-dns.com` + - Set _Type_ to `A` + - Set _Address_ to `94.140.14.49` + - Set _TTL_ to `1d 00:00:00` + - Repeat the process to create an identical entry, but with _Address_ set to `94.140.14.59` 5. Disable Peer DNS on DHCP Client: - - Go to _IP_ → _DHCP Client_ - - Double-click the client used for your Internet connection (usually on the WAN interface) - - Uncheck _Use Peer DNS_ - - Click _OK_ + - Go to _IP_ → _DHCP Client_ + - Double-click the client used for your Internet connection (usually on the WAN interface) + - Uncheck _Use Peer DNS_ + - Click _OK_ 6. Test and verify: - - You might need to reboot your MikroTik router for all changes to take effect - - Clear your browser’s DNS cache. You can use a tool like [https://www.dnsleaktest.com](https://www.dnsleaktest.com/) to check if your DNS requests are now routed through AdGuard + - You might need to reboot your MikroTik router for all changes to take effect + - Clear your browser’s DNS cache. You can use a tool like [https://www.dnsleaktest.com](https://www.dnsleaktest.com/) to check if your DNS requests are now routed through AdGuard ## My router does not support DNS-over-HTTPS Use these instructions if your MikroTik router does not support DNS-over-HTTPS configuration: 1. Access your MikroTik router: - - Open your web browser and go to your router’s IP address (usually `192.168.88.1`) - - Alternatively, you can use Winbox to connect to your MikroTik router - - Enter your administrator username and password + - Open your web browser and go to your router’s IP address (usually `192.168.88.1`) + - Alternatively, you can use Winbox to connect to your MikroTik router + - Enter your administrator username and password 2. Configure Plain DNS: - - Go to _IP_ → _DNS_ - - In the _Servers_ section, add the following AdGuard DNS servers: - - IPv4: `94.140.14.49` and `94.140.14.59` - - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` - - Dedicated IPv6: Private AdGuard DNS supports dedicated IPv6 addresses. To find them, open the Dashboard, click _Settings_ next to your device → _Plain DNS server addresses_ → _Dedicated IPv6 addresses_. - - Click _OK_ + - Go to _IP_ → _DNS_ + - In the _Servers_ section, add the following AdGuard DNS servers: + - IPv4: `94.140.14.49` and `94.140.14.59` + - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` + - Dedicated IPv6: Private AdGuard DNS supports dedicated IPv6 addresses. To find them, open the Dashboard, click _Settings_ next to your device → _Plain DNS server addresses_ → _Dedicated IPv6 addresses_. + - Click _OK_ 3. Disable Peer DNS on DHCP Client: - - Go to _IP_ → _DHCP Client_ - - Double-click the client used for your Internet connection (usually on the WAN interface) - - Uncheck _Use Peer DNS_ - - Click _OK_ + - Go to _IP_ → _DHCP Client_ + - Double-click the client used for your Internet connection (usually on the WAN interface) + - Uncheck _Use Peer DNS_ + - Click _OK_ diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/openwrt.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/openwrt.md index ab686a761..6f45408f5 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/openwrt.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/openwrt.md @@ -9,71 +9,71 @@ OpenWRT routers use an open source, Linux-based operating system that provides t - **Command-line instructions**. Install the required packages. DNS encryption should be enabled automatically. - ```# Install packages - 1. opkg update - 2. opkg install https-dns-proxy + ```# Install packages + 1. opkg update + 2. opkg install https-dns-proxy - ``` + ``` - **Web interface**. If you want to manage the settings using web interface, install the necessary packages. - ```# Install packages - 1. opkg update - 2. opkg install luci-app-https-dns-proxy - 3. /etc/init.d/rpcd restart - ``` + ```# Install packages + 1. opkg update + 2. opkg install luci-app-https-dns-proxy + 3. /etc/init.d/rpcd restart + ``` Navigate to _LuCI_ → _Services_ → _HTTPS DNS Proxy_ to configure the https-dns-proxy. - **Configure DoH provider**. https-dns-proxy is configured with Google DNS and Cloudflare DNS by default. You need to change it to AdGuard DoH. Specify several resolvers to improve fault tolerance. - ```# Configure DoH provider - 1. while uci -q delete https-dns-proxy.@https-dns-proxy[0]; do :; done - 2. uci set https-dns-proxy.dns="https-dns-proxy" - 3. uci set https-dns-proxy.dns.bootstrap_dns="94.140.14.49,94.140.14.59" - 4. uci set https-dns-proxy.dns.resolver_url="https://d.adguard-dns.com/dns-query/{Your_Private_Server_ID}" - 5. uci set https-dns-proxy.dns.listen_addr="127.0.0.1" - 6. uci set https-dns-proxy.dns.listen_port="5053" - 7. uci commit https-dns-proxy - 8. /etc/init.d/https-dns-proxy restart - ``` + ```# Configure DoH provider + 1. while uci -q delete https-dns-proxy.@https-dns-proxy[0]; do :; done + 2. uci set https-dns-proxy.dns="https-dns-proxy" + 3. uci set https-dns-proxy.dns.bootstrap_dns="94.140.14.49,94.140.14.59" + 4. uci set https-dns-proxy.dns.resolver_url="https://d.adguard-dns.com/dns-query/{Your_Private_Server_ID}" + 5. uci set https-dns-proxy.dns.listen_addr="127.0.0.1" + 6. uci set https-dns-proxy.dns.listen_port="5053" + 7. uci commit https-dns-proxy + 8. /etc/init.d/https-dns-proxy restart + ``` ## Configure DNS-over-TLS - **Command-line instructions**. [Disable](https://openwrt.org/docs/guide-user/base-system/dhcp_configuration#disabling_dns_role) Dnsmasq DNS role or remove it completely optionally [replacing](https://openwrt.org/docs/guide-user/base-system/dhcp_configuration#replacing_dnsmasq_with_odhcpd_and_unbound) its DHCP role with odhcpd. - ```# Install packages - 1. opkg update - 2. opkg install unbound-daemon ca-certificates - ``` + ```# Install packages + 1. opkg update + 2. opkg install unbound-daemon ca-certificates + ``` LAN clients and the local system should use Unbound as a primary resolver assuming that Dnsmasq is disabled. - **Web interface**. If you want to manage the settings using web interface, install the necessary packages. - ```# Install packages - 1. opkg update - 2. opkg install luci-app-unbound ca-certificates - 3. /etc/init.d/rpcd restart - ``` + ```# Install packages + 1. opkg update + 2. opkg install luci-app-unbound ca-certificates + 3. /etc/init.d/rpcd restart + ``` Navigate to _LuCI_ → _Services_ → _Recursive DNS_ to configure Unbound. - **Configure AdGuard DNS-over-TLS**. - ```1. uci add unbound zone - 2. uci set unbound.@zone[-1].enabled="1" - 3. uci set unbound.@zone[-1].fallback="0" - 4. uci set unbound.@zone[-1].zone_type="forward_zone" - 5. uci add_list unbound.@zone[-1].zone_name="." - 6. uci set unbound.@zone[-1].tls_upstream="1" - 7. uci set unbound.@zone[-1].tls_index="{Your_Private_Server_ID}.d.adguard-dns.com" - 8. uci add_list unbound.@zone[-1].server="94.140.14.49" - 9. uci add_list unbound.@zone[-1].server="94.140.14.59" - 10. uci add_list unbound.@zone[-1].server="2a10:50c0::ded:ff" - 11. uci add_list unbound.@zone[-1].server="2a10:50c0::dad:ff" - 12. uci commit unbound - 13. /etc/init.d/unbound restart - ``` + ```1. uci add unbound zone + 2. uci set unbound.@zone[-1].enabled="1" + 3. uci set unbound.@zone[-1].fallback="0" + 4. uci set unbound.@zone[-1].zone_type="forward_zone" + 5. uci add_list unbound.@zone[-1].zone_name="." + 6. uci set unbound.@zone[-1].tls_upstream="1" + 7. uci set unbound.@zone[-1].tls_index="{Your_Private_Server_ID}.d.adguard-dns.com" + 8. uci add_list unbound.@zone[-1].server="94.140.14.49" + 9. uci add_list unbound.@zone[-1].server="94.140.14.59" + 10. uci add_list unbound.@zone[-1].server="2a10:50c0::ded:ff" + 11. uci add_list unbound.@zone[-1].server="2a10:50c0::dad:ff" + 12. uci commit unbound + 13. /etc/init.d/unbound restart + ``` ## Use your router admin panel @@ -85,8 +85,8 @@ Use these instructions if your Keenetic router does not support DNS-over-HTTPS o 4. Select your Wi-Fi network or wired connection. 5. Scroll down to IPv4 address or IPv6 address, depending on the IP version you want to configure. 6. Under _Use custom DNS servers_, enter the IP addresses of the DNS servers you want to use. You can enter multiple DNS servers, separated by spaces or commas: - - IPv4: `94.140.14.49` and `94.140.14.59` - - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` + - IPv4: `94.140.14.49` and `94.140.14.59` + - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` 7. Optionally, you can enable DNS forwarding if you want the router to act as a DNS forwarder for devices on your network. 8. Save the settings. 9. Link your IP (or your dedicated IP if you have a Team subscription). diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/opnsense.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/opnsense.md index d7c06a0a3..911b2b0de 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/opnsense.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/opnsense.md @@ -15,8 +15,8 @@ Use these instructions if your Keenetic router does not support DNS-over-HTTPS o 4. On the _DHCP Server_ page, select the interface that you want to configure the DNS settings for (e.g., LAN, WLAN). 5. Scroll down to _DNS Servers_. 6. Choose _Manual DNS_. Select _Use These DNS Servers_ or _Specify DNS Server Manually_ and enter the following DNS server addresses: - - IPv4: `94.140.14.49` and `94.140.14.59` - - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` + - IPv4: `94.140.14.49` and `94.140.14.59` + - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` 7. Save the settings. 8. Optionally, you can enable DNSSEC for enhanced security. 9. Link your IP (or your dedicated IP if you have a Team subscription). diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/synology-nas.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/synology-nas.md index 91f4b90a7..7a287e167 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/synology-nas.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/synology-nas.md @@ -15,8 +15,8 @@ Use these instructions if your Keenetic router does not support DNS-over-HTTPS o 4. Select _Network Interface_ or _Network Settings_. 5. Select your Wi-Fi network or wired connection. 6. Choose _Manual DNS_. Select _Use These DNS Servers_ or _Specify DNS Server Manually_ and enter the following DNS server addresses: - - IPv4: `94.140.14.49` and `94.140.14.59` - - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` + - IPv4: `94.140.14.49` and `94.140.14.59` + - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` 7. Save the settings. 8. Link your IP (or your dedicated IP if you have a Team subscription). diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/unifi.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/unifi.md index 11aea58ad..2ddd5f519 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/unifi.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/unifi.md @@ -17,9 +17,9 @@ Obtain the DNS-over-HTTPS URL that is used to calculate the DNS Stamp URL. 1. Go to the AdGuard DNS Private Dashboard. 2. Proceed to _Encrypted DNS_ → _Custom_ and enter the following DNS server settings: - - Device type: 'Router' - - Device brand: 'Unifi' - - Device name: Use your Unifi device name + - Device type: 'Router' + - Device brand: 'Unifi' + - Device name: Use your Unifi device name 3. Click _Next_. 4. Scroll to _Use DNS server addresses_ → _DNS-over-HTTPS_ and take note of the DNS-over-HTTPS URL (e.g., https://d.adguard-dns.com/dns-query/123456abc). @@ -29,8 +29,8 @@ Generate a DNS stamp using the [DNSCrypt DNS Stamp Calculator](https://dnscrypt. 2. Host name: d.adguard-dns.com 3. Path: /dns-query/123456abc (replace 123456abc with the value obtained from your AdGuard DNS Private Dashboard) 4. Untick - - No filter - - No logs + - No filter + - No logs 5. Copy the DNS stamp URL (e.g., sdns://AgcAAAAAA…) Turn on DNS-over-HTTPS in UniFi. @@ -39,8 +39,8 @@ Turn on DNS-over-HTTPS in UniFi. 2. Go to _Settings_ → _Security_. 3. Click _Protection_. 4. Proceed to _Encrypted DNS_ → _Custom_ and enter the following DNS server addresses. - - Server Name: 'AdGuard DNS' - - DNS Stamp: DNS stamp URL copied from above + - Server Name: 'AdGuard DNS' + - DNS Stamp: DNS stamp URL copied from above 5. Click _Save_. ## Use your router admin panel @@ -51,15 +51,15 @@ Use these instructions if your UniFi router does not support the DNS-over-HTTPS 2. Go to _Settings_ → _Networks_. 3. Click _Edit Network_ → _WAN_. 4. Proceed to _Common Settings_ → _DNS Server_ and enter the following DNS server addresses: - - IPv4: `94.140.14.49` and `94.140.14.59` - - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` + - IPv4: `94.140.14.49` and `94.140.14.59` + - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` 5. Click _Save_. 6. Return to _Network_. 7. Choose _Edit Network_ → _LAN_. 8. Find _DHCP Name Server_ and select _Manual_. 9. Enter your gateway address in the _DNS Server 1_ field. Alternatively, you can enter the AdGuard DNS server addresses in the _DNS Server 1_ and _DNS Server 2_ fields: - - IPv4: `94.140.14.49` and `94.140.14.59` - - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` + - IPv4: `94.140.14.49` and `94.140.14.59` + - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` 10. Save the settings. 11. Link your IP (or your dedicated IP if you have a Team subscription). - [Dedicated IPs](private-dns/connect-devices/other-options/dedicated-ip.md) diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/universal.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/universal.md index e93e48674..2723bf95e 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/universal.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/connect-devices/routers/universal.md @@ -8,21 +8,21 @@ Here are some general instructions for setting up Private AdGuard DNS on routers ## Use your router admin panel 1. Open the preferences for your router. Usually you can access them from your browser. Depending on the model of your router, try entering one the following addresses: - - Linksys and Asus routers typically use: [http://192.168.1.1](http://192.168.1.1/) - - Netgear routers typically use: [http://192.168.0.1](http://192.168.0.1/) or [http://192.168.1.1](http://192.168.1.1/) D-Link routers typically use [http://192.168.0.1](http://192.168.0.1/) - - Ubiquiti routers typically use: [http://unifi.ubnt.com](http://unifi.ubnt.com/) + - Linksys and Asus routers typically use: [http://192.168.1.1](http://192.168.1.1/) + - Netgear routers typically use: [http://192.168.0.1](http://192.168.0.1/) or [http://192.168.1.1](http://192.168.1.1/) D-Link routers typically use [http://192.168.0.1](http://192.168.0.1/) + - Ubiquiti routers typically use: [http://unifi.ubnt.com](http://unifi.ubnt.com/) 2. Enter the router’s password. - :::note Important + :::note Important - If the password is unknown, you can often reset it by pressing a button on the router; it will also reset the router to its factory settings. Some models have a dedicated management application, which should already be installed on your computer. + If the password is unknown, you can often reset it by pressing a button on the router; it will also reset the router to its factory settings. Some models have a dedicated management application, which should already be installed on your computer. - ::: + ::: 3. Find where DNS settings are located in the router’s admin console. Change the listed DNS addresses to the following addresses: - - IPv4: `94.140.14.49` and `94.140.14.59` - - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` + - IPv4: `94.140.14.49` and `94.140.14.59` + - IPv6: `2a10:50c0:0:0:0:0:ded:ff` and `2a10:50c0:0:0:0:0:dad:ff` 4. Save the settings. diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/rate-limit.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/rate-limit.md index 503005175..a178b5326 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/rate-limit.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/rate-limit.md @@ -19,6 +19,6 @@ If you are subscribed to AdGuard DNS _Team_ or _Enterprise_ plan, you can reques 2. Tap _request a limit increase_ to contact our support team and apply for the rate limit increase. You will need to provide your CIDR and the limit you want to have - ![Rate limit](https://cdn.adtidy.org/content/kb/dns/private/rate_limit.png) + ![Rate limit](https://cdn.adtidy.org/content/kb/dns/private/rate_limit.png) 3. Your request will be reviewed within 1–3 working days. We will contact you about the changes by email diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index cd2a4ad76..143c85ffa 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,9 +3,7 @@ title: Parental control sidebar_position: 5 --- -## What is it - -Parental control is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. ## How to set it up @@ -23,28 +21,40 @@ Blocks websites with inappropriate and adult content. Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -![Safe search \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) - ### YouTube restricted mode Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -![Restricted mode \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) - ### Blocked services and websites -AdGuard DNS blocks access to popular services with one click. It’s useful if you don’t want connected devices to visit Instagram and YouTube, for example. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. ![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) ### Block websites by category -This feature lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. + +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) + +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. + +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### Schedule off time +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -Enables parental controls on selected days with a specified time interval. For example, you may have allowed your child to watch YouTube videos only until 23:00 on weekdays. But on weekends, this access is not restricted. Customize the schedule to your liking and block access to selected sites during the hours you want. +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![Schedule \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index b21375a03..1e626b858 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ These are further divided into sub-categories: - **CDN**: request connected to Content Delivery Network (CDN), a worldwide network of proxy servers that speeds the delivery of content to end users - **Other** -### Top companies +## Top companies In this table, we not only show the names of the most visited or most blocked companies, but also display information about which domains are being requested from or which domains are being blocked the most. diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..23c091aa4 --- /dev/null +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Required | Description | Example | +| :---------------- | :------------ | :------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | No | Detected account ID, if any. | `1234` | +| `DnsServerId` | string | No | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | string | No | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | string | No | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | string | No | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | string | Yes | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | string | No | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | string | No | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Yes | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | No | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Yes | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Yes | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Yes | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Yes | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Yes | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Yes | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Yes | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | string | No | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Yes | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Yes | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## FAQ + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 90ecc6874..3367affbe 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Query log sidebar_position: 5 --- -## What is Query log +## What is Query log? -Query log is a useful tool for working with AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. It allows you to view all requests made by your devices during the selected time period and sort requests by status, type, company, device, country. ## How to use it -Here’s what you can see and what you can do in the _Query log_. +Here’s what you can see and what you can do in _Query log_. ### Detailed information on requests -![Requests info \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Blocking and unblocking domains Requests can be blocked and unblocked without leaving the log, using the available tools. -![Unblock domain \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Sorting requests diff --git a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index b9047787e..4281c19bb 100644 --- a/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/sk/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS provides a wide range of useful tools for monitoring queries: - [Traffic destination](/private-dns/statistics-and-log/traffic-destination.md) - [Companies](/private-dns/statistics-and-log/companies.md) - [Query log](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/sl/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/sl/docusaurus-plugin-content-docs/current/general/dns-providers.md index 614bfba98..15348bd48 100644 --- a/i18n/sl/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/sl/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### Non-filtering - -| Protocol | Address | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| Protocol | Address | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Ad + malware blocking - -| Protocol | Address | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Ad + malware + social media blocking - -| Protocol | Address | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Ad + malware + adult + gambling blocking - -| Protocol | Address | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Ad + malware + adult + gambling + social media blocking - -| Protocol | Address | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### Unsecured -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protocol | Address | | | -------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index cd2a4ad76..143c85ffa 100644 --- a/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,9 +3,7 @@ title: Parental control sidebar_position: 5 --- -## What is it - -Parental control is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. ## How to set it up @@ -23,28 +21,40 @@ Blocks websites with inappropriate and adult content. Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -![Safe search \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) - ### YouTube restricted mode Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -![Restricted mode \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) - ### Blocked services and websites -AdGuard DNS blocks access to popular services with one click. It’s useful if you don’t want connected devices to visit Instagram and YouTube, for example. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. ![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) ### Block websites by category -This feature lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. + +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) + +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. + +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### Schedule off time +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -Enables parental controls on selected days with a specified time interval. For example, you may have allowed your child to watch YouTube videos only until 23:00 on weekdays. But on weekends, this access is not restricted. Customize the schedule to your liking and block access to selected sites during the hours you want. +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![Schedule \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index b21375a03..1e626b858 100644 --- a/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ These are further divided into sub-categories: - **CDN**: request connected to Content Delivery Network (CDN), a worldwide network of proxy servers that speeds the delivery of content to end users - **Other** -### Top companies +## Top companies In this table, we not only show the names of the most visited or most blocked companies, but also display information about which domains are being requested from or which domains are being blocked the most. diff --git a/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..23c091aa4 --- /dev/null +++ b/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Required | Description | Example | +| :---------------- | :------------ | :------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | No | Detected account ID, if any. | `1234` | +| `DnsServerId` | string | No | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | string | No | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | string | No | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | string | No | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | string | Yes | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | string | No | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | string | No | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Yes | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | No | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Yes | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Yes | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Yes | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Yes | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Yes | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Yes | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Yes | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | string | No | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Yes | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Yes | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## FAQ + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 90ecc6874..3367affbe 100644 --- a/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Query log sidebar_position: 5 --- -## What is Query log +## What is Query log? -Query log is a useful tool for working with AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. It allows you to view all requests made by your devices during the selected time period and sort requests by status, type, company, device, country. ## How to use it -Here’s what you can see and what you can do in the _Query log_. +Here’s what you can see and what you can do in _Query log_. ### Detailed information on requests -![Requests info \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Blocking and unblocking domains Requests can be blocked and unblocked without leaving the log, using the available tools. -![Unblock domain \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Sorting requests diff --git a/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index b9047787e..4281c19bb 100644 --- a/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/sl/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS provides a wide range of useful tools for monitoring queries: - [Traffic destination](/private-dns/statistics-and-log/traffic-destination.md) - [Companies](/private-dns/statistics-and-log/companies.md) - [Query log](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/sr/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/sr/docusaurus-plugin-content-docs/current/general/dns-providers.md index 1d696b11a..050a620c6 100644 --- a/i18n/sr/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/sr/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### Bez filtriranja - -| Protokol | Adresa | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| Protokol | Adresa | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Ad + malware blocking - -| Protokol | Adresa | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Ad + malware + social media blocking - -| Protokol | Adresa | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Ad + malware + adult + gambling blocking - -| Protokol | Adresa | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Ad + malware + adult + gambling + social media blocking - -| Protokol | Adresa | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### Unsecured -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protokol | Adresa | | | -------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index cd2a4ad76..143c85ffa 100644 --- a/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,9 +3,7 @@ title: Parental control sidebar_position: 5 --- -## What is it - -Parental control is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. ## How to set it up @@ -23,28 +21,40 @@ Blocks websites with inappropriate and adult content. Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -![Safe search \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) - ### YouTube restricted mode Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -![Restricted mode \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) - ### Blocked services and websites -AdGuard DNS blocks access to popular services with one click. It’s useful if you don’t want connected devices to visit Instagram and YouTube, for example. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. ![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) ### Block websites by category -This feature lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. + +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) + +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. + +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### Schedule off time +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -Enables parental controls on selected days with a specified time interval. For example, you may have allowed your child to watch YouTube videos only until 23:00 on weekdays. But on weekends, this access is not restricted. Customize the schedule to your liking and block access to selected sites during the hours you want. +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![Schedule \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index b21375a03..1e626b858 100644 --- a/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ These are further divided into sub-categories: - **CDN**: request connected to Content Delivery Network (CDN), a worldwide network of proxy servers that speeds the delivery of content to end users - **Other** -### Top companies +## Top companies In this table, we not only show the names of the most visited or most blocked companies, but also display information about which domains are being requested from or which domains are being blocked the most. diff --git a/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..dd85ab8c5 --- /dev/null +++ b/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Required | Description | Example | +| :---------------- | :------------ | :------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | No | Detected account ID, if any. | `1234` | +| `DnsServerId` | string | No | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | string | No | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | string | No | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | string | No | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | string | Yes | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | string | No | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | string | No | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Yes | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | No | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Yes | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Yes | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Yes | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Yes | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Yes | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Yes | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Yes | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | string | No | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Yes | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Yes | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## Često postavljana pitanja + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 90ecc6874..3367affbe 100644 --- a/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Query log sidebar_position: 5 --- -## What is Query log +## What is Query log? -Query log is a useful tool for working with AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. It allows you to view all requests made by your devices during the selected time period and sort requests by status, type, company, device, country. ## How to use it -Here’s what you can see and what you can do in the _Query log_. +Here’s what you can see and what you can do in _Query log_. ### Detailed information on requests -![Requests info \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Blocking and unblocking domains Requests can be blocked and unblocked without leaving the log, using the available tools. -![Unblock domain \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Sorting requests diff --git a/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index b9047787e..4281c19bb 100644 --- a/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/sr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS provides a wide range of useful tools for monitoring queries: - [Traffic destination](/private-dns/statistics-and-log/traffic-destination.md) - [Companies](/private-dns/statistics-and-log/companies.md) - [Query log](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/tr/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/tr/docusaurus-plugin-content-docs/current/general/dns-providers.md index ae8341307..1fa2b2675 100644 --- a/i18n/tr/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/tr/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [AdGuard'a ekle](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [AdGuard VPN'e ekle](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [AdGuard'a ekle](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [AdGuard VPN'e ekle](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### Non-filtering - -| Protokol | Adres | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [AdGuard'a ekle](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [AdGuard VPN'e ekle](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [AdGuard'a ekle](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [AdGuard VPN'e ekle](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| Protokol | Adres | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [AdGuard'a ekle](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [AdGuard VPN'e ekle](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [AdGuard'a ekle](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [AdGuard VPN'e ekle](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Reklam + kötü amaçlı yazılım engelleme - -| Protokol | Adres | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [AdGuard'a ekle](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [AdGuard VPN'e ekle](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [AdGuard'a ekle](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [AdGuard VPN'e ekle](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Reklam + kötü amaçlı yazılım + sosyal medya engelleme - -| Protokol | Adres | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [AdGuard'a ekle](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [AdGuard VPN'e ekle](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [AdGuard'a ekle](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [AdGuard VPN'e ekle](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Reklam + kötü amaçlı yazılım + yetişkin + kumar engelleme - -| Protokol | Adres | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [AdGuard'a ekle](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [AdGuard VPN'e ekle](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [AdGuard'a ekle](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [AdGuard VPN'e ekle](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Reklam + kötü amaçlı yazılım + yetişkin + kumar + sosyal medya engelleme - -| Protokol | Adres | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [AdGuard'a ekle](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [AdGuard VPN'e ekle](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [AdGuard'a ekle](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [AdGuard VPN'e ekle](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### Unsecured -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protokol | Adres | | | -------------- | ------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md b/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md index 31900f915..3bb637223 100644 --- a/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md +++ b/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md @@ -9,7 +9,7 @@ Kimlik doğrulamalı DNS-over-HTTPS, seçtiğiniz sunucuya erişmek için bir ku Bu, yetkisiz kullanıcıların erişmesini önlemeye yardımcı olur ve güvenliği artırır. Ayrıca, belirli profiller için diğer protokollerin kullanımını kısıtlayabilirsiniz. Bu özellik, DNS sunucu adresinizin başkaları tarafından bilindiği durumlarda özellikle kullanışlıdır. Parola ekleyerek erişimi engelleyebilir ve yalnızca sizin kullanabilmenizi sağlayabilirsiniz. -## Nasıl ayarlanır +## How to set it up :::note Uyumluluk diff --git a/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md b/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md index 138b10290..eef7c61a6 100644 --- a/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md +++ b/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/server-and-settings/access.md @@ -7,7 +7,7 @@ Erişim ayarlarını yapılandırarak AdGuard DNS'inizi yetkisiz erişime karş Engellenen istekler Sorgu Günlüğünde görüntülenmeyecek ve toplam limite dâhil edilmeyecektir. -## Nasıl ayarlanır +## How to set it up ### İzin verilen istemciler diff --git a/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index 98d26d32e..b9155a21f 100644 --- a/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,48 +3,58 @@ title: Ebeveyn denetimi sidebar_position: 5 --- -## Bu nedir +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. -Parental control is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. +## How to set it up -## Nasıl ayarlanır +You can flexibly configure all features on your servers, including the parental control feature. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. -Sunucularınızdaki ebeveyn denetimi özelliği de dâhil olmak üzere tüm özellikleri esnek bir şekilde yapılandırabilirsiniz. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. +Then, go to the settings of the selected server and enable the required configurations. -Daha sonra seçili sunucunun ayarlarına giderek gerekli yapılandırmaları etkinleştirin. +### Block adult websites -### Yetişkin siteleri engelleme +Blocks websites with inappropriate and adult content. -Uygunsuz ve yetişkinlere yönelik içeriğe sahip siteleri engeller. +![Blocked website \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) -![Engellenen site \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) +### Safe search -### Güvenli arama +Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave ve Ecosia'dan uygunsuz sonuçları kaldırır. +### YouTube restricted mode -![Güvenli arama \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) +Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -### YouTube kısıtlı mod +### Blocked services and websites -YouTube'daki videoların altındaki yorumları görüntüleme ve gönderme ve 18+ içeriklerle etkileşim kurma seçeneğini kaldırır. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. -![Kısıtlı mod \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) +![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) -### Engellenen hizmetler ve siteler +### Block websites by category -AdGuard DNS, tek tıklamayla popüler hizmetlere erişimi engeller. It’s useful if you don’t want connected devices to visit Instagram and YouTube, for example. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. -![Engellenen hizmetler \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) -### Siteleri kategoriye göre engelleme +### Pause schedule -Bu özellik, _Yetişkin içerik_, _Oyunlar_, _Bankacılık_ ve _İletişim_ dâhil olmak üzere 20'den fazla kategori arasından seçim yaparak belirli site kategorilerine erişimi kısıtlamanıza olanak tanır. Örneğin, alkol, tütün veya uyuşturucu hakkında bilgi içeren siteleri engellerseniz, seçilen cihaz artık bu kategorilere giren sayfaları açamayacaktır. +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. -![Kategori tabanlı engelleme \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. -### Plan kapanış zamanı +To set up a pause schedule: -Belirli bir zaman aralığıyla seçilen günlerde ebeveyn denetimlerini etkinleştirir. Örneğin, çocuğunuzun YouTube videolarını sadece hafta içi 23:00'e kadar izlemesine izin vermiş olabilirsiniz. Ancak hafta sonları bu erişim kısıtlanmamaktadır. Planınızı istediğiniz gibi özelleştirin ve istediğiniz saatlerde seçili sitelere erişimi engelleyin. +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. -![Plan \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. + +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) + +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. + +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. + +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index 725e63b24..20dec9b05 100644 --- a/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ Bunlar da kendi aralarında alt kategorilere ayrılır: - **CDN**: request connected to Content Delivery Network (CDN), a worldwide network of proxy servers that speeds the delivery of content to end users - **Diğer** -### Başlıca şirketler +## Başlıca şirketler Bu tabloda sadece en çok ziyaret edilen veya en çok engellenen şirketlerin adlarını göstermekle kalmıyor, aynı zamanda en çok hangi alan adlarından istek yapıldığı veya hangi alan adlarının engellendiğine ilişkin bilgileri de gösteriyoruz. diff --git a/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..d0a1afc18 --- /dev/null +++ b/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Gerekli | Açıklama | Example | +| :---------------- | :------------ | :------ | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | Hayır | Detected account ID, if any. | `1234` | +| `DnsServerId` | dize | Hayır | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | dize | Hayır | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | dize | Hayır | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | dize | Hayır | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | dize | Evet | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | dize | Hayır | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | dize | Hayır | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Evet | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | Hayır | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Evet | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Evet | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Evet | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Evet | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Evet | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Evet | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Evet | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | dize | Hayır | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Evet | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Evet | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## SSS + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index a4171b4d3..35539cc20 100644 --- a/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Sorgu günlüğü sidebar_position: 5 --- -## Sorgu günlüğü nedir +## What is Query log? -Sorgu günlüğü, AdGuard DNS ile çalışmak için faydalı bir araçtır. +_Query log_ is a useful tool for working with AdGuard DNS. Seçilen zaman aralığında cihazlarınız tarafından yapılan tüm istekleri görüntülemenize ve istekleri duruma, türe, şirkete, cihaza, ülkeye göre sıralamanıza olanak tanır. ## Bu nasıl kullanılır -Here’s what you can see and what you can do in the _Query log_. +Here’s what you can see and what you can do in _Query log_. ### İstekler hakkında detaylı bilgi -![İstekler bilgisi \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Alan adlarını engelleme ve engeli kaldırma İstekler, mevcut araçlar kullanılarak günlükten çıkmadan engellenebilir ve engeli kaldırılabilir. -![Alan adının engelini kaldır \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### İstekleri sıralama diff --git a/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index d4a33c94e..e403d309c 100644 --- a/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/tr/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS, sorguları izlemek için çok çeşitli kullanışlı araçlar sağ - [Trafik istikameti](/private-dns/statistics-and-log/traffic-destination.md) - [Şirketler](/private-dns/statistics-and-log/companies.md) - [Sorgu günlüğü](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/vi/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/vi/docusaurus-plugin-content-docs/current/general/dns-providers.md index 614bfba98..15348bd48 100644 --- a/i18n/vi/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/vi/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### Non-filtering - -| Protocol | Address | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| Protocol | Address | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Ad + malware blocking - -| Protocol | Address | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Ad + malware + social media blocking - -| Protocol | Address | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Ad + malware + adult + gambling blocking - -| Protocol | Address | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Ad + malware + adult + gambling + social media blocking - -| Protocol | Address | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### Unsecured -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protocol | Address | | | -------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index cd2a4ad76..143c85ffa 100644 --- a/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,9 +3,7 @@ title: Parental control sidebar_position: 5 --- -## What is it - -Parental control is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. ## How to set it up @@ -23,28 +21,40 @@ Blocks websites with inappropriate and adult content. Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -![Safe search \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) - ### YouTube restricted mode Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -![Restricted mode \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) - ### Blocked services and websites -AdGuard DNS blocks access to popular services with one click. It’s useful if you don’t want connected devices to visit Instagram and YouTube, for example. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. ![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) ### Block websites by category -This feature lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. + +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) + +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. + +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### Schedule off time +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -Enables parental controls on selected days with a specified time interval. For example, you may have allowed your child to watch YouTube videos only until 23:00 on weekdays. But on weekends, this access is not restricted. Customize the schedule to your liking and block access to selected sites during the hours you want. +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![Schedule \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index b21375a03..1e626b858 100644 --- a/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ These are further divided into sub-categories: - **CDN**: request connected to Content Delivery Network (CDN), a worldwide network of proxy servers that speeds the delivery of content to end users - **Other** -### Top companies +## Top companies In this table, we not only show the names of the most visited or most blocked companies, but also display information about which domains are being requested from or which domains are being blocked the most. diff --git a/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..23c091aa4 --- /dev/null +++ b/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Required | Description | Example | +| :---------------- | :------------ | :------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | No | Detected account ID, if any. | `1234` | +| `DnsServerId` | string | No | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | string | No | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | string | No | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | string | No | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | string | Yes | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | string | No | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | string | No | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Yes | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | No | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Yes | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Yes | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Yes | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Yes | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Yes | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Yes | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Yes | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | string | No | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Yes | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Yes | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## FAQ + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 90ecc6874..3367affbe 100644 --- a/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Query log sidebar_position: 5 --- -## What is Query log +## What is Query log? -Query log is a useful tool for working with AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. It allows you to view all requests made by your devices during the selected time period and sort requests by status, type, company, device, country. ## How to use it -Here’s what you can see and what you can do in the _Query log_. +Here’s what you can see and what you can do in _Query log_. ### Detailed information on requests -![Requests info \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Blocking and unblocking domains Requests can be blocked and unblocked without leaving the log, using the available tools. -![Unblock domain \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Sorting requests diff --git a/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index b9047787e..4281c19bb 100644 --- a/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/vi/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS provides a wide range of useful tools for monitoring queries: - [Traffic destination](/private-dns/statistics-and-log/traffic-destination.md) - [Companies](/private-dns/statistics-and-log/companies.md) - [Query log](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/zh-CN/code.json b/i18n/zh-CN/code.json index 0e8de2eb7..0ee3b0532 100644 --- a/i18n/zh-CN/code.json +++ b/i18n/zh-CN/code.json @@ -485,35 +485,35 @@ "description": "The title of the page for a blog author" }, "theme.blog.authorsList.pageTitle": { - "message": "Authors", + "message": "作者", "description": "The title of the authors page" }, "theme.blog.authorsList.viewAll": { - "message": "View all authors", + "message": "查看所有作者", "description": "The label of the link targeting the blog authors page" }, "theme.blog.author.noPosts": { - "message": "This author has not written any posts yet.", + "message": "该作者尚未撰写任何文章。", "description": "The text for authors with 0 blog post" }, "theme.contentVisibility.unlistedBanner.title": { - "message": "Unlisted page", + "message": "未公开页面", "description": "The unlisted content banner title" }, "theme.contentVisibility.unlistedBanner.message": { - "message": "This page is unlisted. Search engines will not index it, and only users having a direct link can access it.", + "message": "此页面未公开。搜索引擎不会收录,只有拥有直接链接的用户才能访问。", "description": "The unlisted content banner message" }, "theme.contentVisibility.draftBanner.title": { - "message": "Draft page", + "message": "草稿页", "description": "The draft content banner title" }, "theme.contentVisibility.draftBanner.message": { - "message": "This page is a draft. It will only be visible in dev and be excluded from the production build.", + "message": "此页面为草稿。仅在开发环境中可见,不会包含在生产构建中。", "description": "The draft content banner message" }, "theme.docs.DocCard.categoryDescription.plurals": { - "message": "1 item|{count} items", + "message": "1 项|{count} 项", "description": "The default description for a category card in the generated index about how many items this category includes" } } diff --git a/i18n/zh-CN/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/zh-CN/docusaurus-plugin-content-docs/current/general/dns-providers.md index eafb58679..73851ba6a 100644 --- a/i18n/zh-CN/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/zh-CN/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### 无过滤 - -| 协议 | 地址 | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### 广告拦截 - -| 协议 | 地址 | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### 广告 + 恶意软件拦截 - -| 协议 | 地址 | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### 广告 + 恶意软件 + 社交媒体拦截 - -| 协议 | 地址 | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### 广告 + 恶意软件 + 成人 + 赌博拦截 - -| 协议 | 地址 | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### 广告 + 恶意软件 + 成人 + 赌博 + 社交媒体拦截 - -| 协议 | 地址 | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### 不安全 -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | 协议 | 地址 | | | -------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md b/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md index 1747ef701..46f6de547 100644 --- a/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md +++ b/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/connect-devices/other-options/doh-authentication.md @@ -9,7 +9,7 @@ sidebar_position: 4 这有助于防止未经授权的访问并提高安全性。 此外,还可以限制特定描述文件中使用其他协议。 当其他人知道您的 DNS 服务器地址时,此功能特别有用。 添加密码后,用户可以阻止访问权限,并确保只有您自己可以使用它。 -## 如何设置 +## How to set it up :::note 兼容性 diff --git a/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index fe1f61669..d6aac1d2c 100644 --- a/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,48 +3,58 @@ title: 家长控制 sidebar_position: 5 --- -## 这是什么 +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. -Parental control is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. +## How to set it up -## 如何设置 +You can flexibly configure all features on your servers, including the parental control feature. [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. -用户可以在服务器上灵活配置所有功能,包括家长控制功能。 [In the corresponding article](private-dns/server-and-settings/server-and-settings.md), you can familiarize yourself with what a server is in AdGuard DNS and learn how to create different servers with different sets of settings. +Then, go to the settings of the selected server and enable the required configurations. -然后,进入所选服务器的设置,启用所需的配置。 +### Block adult websites -### 拦截成人网站 +Blocks websites with inappropriate and adult content. -拦截含有不适当和成人内容的网站。 +![Blocked website \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) -![已拦截的网站 \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/adult_blocked.png) +### Safe search -### 安全搜索 +Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -删除来自 Google、Bing、DuckDuckGo、Yandex、Pixabay、Brave 和 Ecosia 的不适当结果。 +### YouTube restricted mode -![安全搜索 \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) +Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -### YouTube 受限模式 +### Blocked services and websites -删除在 YouTube 上查看和发布评论的选项,并限制与 18+ 内容的互动。 +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. -![受限模式 \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) +![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) -### 已阻止的服务及网站 +### Block websites by category -AdGuard DNS 只需一键即可阻止访问热门服务。 It’s useful if you don’t want connected devices to visit Instagram and YouTube, for example. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. -![已拦截的服务 \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) -### Block websites by category +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. -This feature lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### 设置禁用时间 +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -在指定日期和时间间隔内启用家长控制。 例如,在工作日,您允许孩子在 23:00 之前观看 YouTube 视频, 但在周末,没有时间限制。 可以根据您的喜好定制时间段,并在您希望的时间段内阻止访问指定的网站。 +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![定时 \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index 7e4da282f..52bbfa247 100644 --- a/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ sidebar_position: 4 - **CDN**:请求连接到内容分发网络(CDN),这是一个全球的代理服务器网络,能够加速内容传递到用户。 - **其他** -### 公司排行 +## 公司排行 在此表格中,我们不仅显示访问最多或已拦截公司的名称,还展示请求或已拦截的域名信息。 diff --git a/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..6ba0b0b0a --- /dev/null +++ b/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | 必填 | 详细信息 | Example | +| :---------------- | :------------ | :- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | 否 | Detected account ID, if any. | `1234` | +| `DnsServerId` | 字符串 | 否 | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | 字符串 | 否 | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | 字符串 | 否 | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | 字符串 | 否 | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | 字符串 | 是 | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | 字符串 | 否 | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | 字符串 | 否 | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | 是 | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | 否 | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | 是 | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | 是 | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | 是 | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | 是 | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | 是 | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | 是 | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | 是 | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | 字符串 | 否 | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | 是 | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | 是 | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## 常见问题 + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 349d10061..09f29ee94 100644 --- a/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: 查询日志 sidebar_position: 5 --- -## 什么是查询日志 +## What is Query log? -查询日志是一个用于与 AdGuard DNS 配合使用的有用工具。 +_Query log_ is a useful tool for working with AdGuard DNS. 它允许用户查看在所选时间周期内您的设备发出的所有请求,并按状态、类型、公司、设备、国家/地区对请求进行排序。 ## 使用方式 -Here’s what you can see and what you can do in the _Query log_. +Here’s what you can see and what you can do in _Query log_. ### 请求的详细信息 -![请求信息 \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### 域名的拦截与取消拦截 您可以不离开日志界面,使用可用工具拦截或取消拦截请求。 -![取消拦截域名 \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### 请求排序 diff --git a/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index 48463cbb5..382997eee 100644 --- a/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/zh-CN/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS 提供广泛的有用工具来监控查询: - [流量终点](/private-dns/statistics-and-log/traffic-destination.md) - [公司](/private-dns/statistics-and-log/companies.md) - [查询日志](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md) diff --git a/i18n/zh-TW/docusaurus-plugin-content-docs/current/general/dns-providers.md b/i18n/zh-TW/docusaurus-plugin-content-docs/current/general/dns-providers.md index 614bfba98..15348bd48 100644 --- a/i18n/zh-TW/docusaurus-plugin-content-docs/current/general/dns-providers.md +++ b/i18n/zh-TW/docusaurus-plugin-content-docs/current/general/dns-providers.md @@ -448,52 +448,6 @@ Hurricane Electric Public Recursor is a free alternative DNS service by Hurrican | DNS-over-HTTPS | `https://ordns.he.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://ordns.he.net/dns-query&name=ordns.he.net) | | DNS-over-TLS | `tls://ordns.he.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://ordns.he.net&name=ordns.he.net) | -### Mullvad - -[Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/) provides publicly accessible DNS with QNAME minimization, endpoints located in Germany, Singapore, Sweden, United Kingdom and United States (Dallas & New York). - -#### Non-filtering - -| Protocol | Address | | -| -------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://dns.mullvad.net/dns-query&name=MullvadDoH) | -| DNS-over-TLS | `tls://dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://dns.mullvad.net&name=MullvadDoT) | - -#### Ad blocking - -| Protocol | Address | | -| -------------- | ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://adblock.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://adblock.dns.mullvad.net/dns-query&name=adblock.dns.mullvad.net) | -| DNS-over-TLS | `tls://adblock.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://adblock.dns.mullvad.net&name=adblock.dns.mullvad.net) | - -#### Ad + malware blocking - -| Protocol | Address | | -| -------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://base.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://base.dns.mullvad.net/dns-query&name=base.dns.mullvad.net) | -| DNS-over-TLS | `tls://base.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://base.dns.mullvad.net&name=base.dns.mullvad.net) | - -#### Ad + malware + social media blocking - -| Protocol | Address | | -| -------------- | -------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://extended.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://extended.dns.mullvad.net/dns-query&name=extended.dns.mullvad.net) | -| DNS-over-TLS | `tls://extended.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://extended.dns.mullvad.net&name=extended.dns.mullvad.net) | - -#### Ad + malware + adult + gambling blocking - -| Protocol | Address | | -| -------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://family.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://family.dns.mullvad.net/dns-query&name=family.dns.mullvad.net) | -| DNS-over-TLS | `tls://family.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://family.dns.mullvad.net&name=family.dns.mullvad.net) | - -#### Ad + malware + adult + gambling + social media blocking - -| Protocol | Address | | -| -------------- | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| DNS-over-HTTPS | `https://all.dns.mullvad.net/dns-query` | [Add to AdGuard](adguard:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=https://all.dns.mullvad.net/dns-query&name=all.dns.mullvad.net) | -| DNS-over-TLS | `tls://all.dns.mullvad.net` | [Add to AdGuard](adguard:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net), [Add to AdGuard VPN](adguardvpn:add_dns_server?address=tls://all.dns.mullvad.net&name=all.dns.mullvad.net) | - ### Nawala Childprotection DNS [Nawala Childprotection DNS](http://nawala.id/) is an anycast Internet filtering system that protects children from inappropriate websites and abusive content. @@ -611,7 +565,7 @@ Regular DNS servers which provide protection from phishing and spyware. They inc #### Unsecured -Unsecured DNS servers don’t provide security blocklists, DNSSEC, or EDNS Client Subnet. +Unsecured DNS servers provide DNSSEC validation across every Quad9 service endpoint, but they don’t provide security blocklists or EDNS Client Subnet. | Protocol | Address | | | -------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md b/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md index cd2a4ad76..143c85ffa 100644 --- a/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md +++ b/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/setting-up-filtering/parental-control.md @@ -3,9 +3,7 @@ title: Parental control sidebar_position: 5 --- -## What is it - -Parental control is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. +_Parental control_ is a set of settings that gives you the flexibility to customize access to certain websites with sensitive content. You can use this feature to restrict your children’s access to adult sites, customize search queries, block the use of popular services, and more. ## How to set it up @@ -23,28 +21,40 @@ Blocks websites with inappropriate and adult content. Removes inappropriate results from Google, Bing, DuckDuckGo, Yandex, Pixabay, Brave, and Ecosia. -![Safe search \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/porn.png) - ### YouTube restricted mode Removes the option to view and post comments under videos and interact with 18+ content on YouTube. -![Restricted mode \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/restricted.png) - ### Blocked services and websites -AdGuard DNS blocks access to popular services with one click. It’s useful if you don’t want connected devices to visit Instagram and YouTube, for example. +Restricts access to popular services with one click. This is useful if you don’t want connected devices to visit certain platforms, such as Instagram and YouTube. ![Blocked services \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/blocked_services.png) ### Block websites by category -This feature lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. +Lets you restrict access to specific categories of websites by choosing from more than 20 categories, including _Adult content_, _Games_, _Banking_, and _Communication_. For example, if you block sites that contain information about alcohol, tobacco, or drugs, the selected device will no longer be able to open pages that fall under those categories. + +![Category-based blocking \*mobile_border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) + +### Pause schedule + +Temporarily suspends Parental control restrictions on selected days and during specified time intervals. You can add one or multiple pause intervals for each day. + +For example, you may allow your child to watch YouTube until 23:00 on weekdays, while leaving access unrestricted on weekends. You can also add an additional pause interval, such as from 13:00 to 15:00 on a weekday. + +To set up a pause schedule: + +1. Go to _Servers_ → select a server → _Parental control_ → _Pause schedule_. +2. Click the **+** button next to the desired day and set the interval in the _Add pause_ dialog. +3. To change an existing interval, click _Edit_. + +You can set multiple intervals for the same day. Intervals on the same day cannot overlap: if you try to create overlapping intervals, you will see a warning and will not be able to save the schedule. -![Category-based blocking \*border](https://cdn.adtidy.org/content/release_notes/dns/v2-18/category_en.png) +![Overlapping intervals \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/overlapping_intervals.png) -### Schedule off time +Select the _All day_ checkbox to pause Parental control for the entire day. This removes all existing pause intervals for that day. -Enables parental controls on selected days with a specified time interval. For example, you may have allowed your child to watch YouTube videos only until 23:00 on weekdays. But on weekends, this access is not restricted. Customize the schedule to your liking and block access to selected sites during the hours you want. +Pause intervals can also span midnight. For example, if you set a pause from 22:00 on Monday to 07:00 on Tuesday, the dashboard will display it as two intervals: Monday, 22:00–00:00, and Tuesday, 00:00–07:00. This does not affect how the pause works. -![Schedule \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/schedule.png) +![Pause past midnight \*mobile](https://cdn.adtidy.org/content/kb/dns/private/new_dns/parental_control/past_midnight.png) diff --git a/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md b/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md index b21375a03..1e626b858 100644 --- a/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md +++ b/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/companies.md @@ -20,7 +20,7 @@ These are further divided into sub-categories: - **CDN**: request connected to Content Delivery Network (CDN), a worldwide network of proxy servers that speeds the delivery of content to end users - **Other** -### Top companies +## Top companies In this table, we not only show the names of the most visited or most blocked companies, but also display information about which domains are being requested from or which domains are being blocked the most. diff --git a/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md b/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md new file mode 100644 index 000000000..11c91ae23 --- /dev/null +++ b/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log-streaming.md @@ -0,0 +1,258 @@ +--- +title: Query log streaming +sidebar_position: 6 +--- + +:::info + +_Query log streaming_ is currently in beta testing. During this phase, configuration and setup are semi-manual and performed in coordination with the AdGuard team. + +::: + +This article describes how to set up and use _Query log streaming_ in AdGuard DNS. This feature allows AdGuard DNS Enterprise users to automatically export raw DNS query events to external storage for security, analysis, or compliance purposes. + +## What is Query log streaming? + +_Query log streaming_ lets AdGuard DNS Enterprise users automatically export raw DNS query events to their own external, S3-compatible storage — without relying on manual API polling. Once exported, these logs can be ingested into SIEM systems, SOC platforms, data lakes, or internal analytics pipelines, giving you programmatic access to raw query data for security monitoring, auditing, and compliance. + +Events are collected and delivered in periodic, compressed batches; delivery timing depends on traffic volume (see the [_Delivery guarantees and limitations_](#delivery-guarantees-and-limitations) section for details). + +## Availability and requirements + +To use _Query log streaming_, the following requirements must be met: + +- **Enterprise plan:** This feature is strictly available to AdGuard DNS Enterprise users. If the account is no longer on an Enterprise plan, the log streaming service will be deactivated. For voluntary deactivation, see the FAQ below. +- **Active Query log:** Your AdGuard DNS configuration must have query logging enabled. +- **S3-compatible bucket:** You must have an active, writeable bucket on Amazon S3 or another S3-compatible cloud storage provider (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). +- **Access credentials:** You must provide the connection parameters and credentials required for AdGuard DNS to write objects to your bucket. + +## How to request setup + +Since configuration is currently handled manually by our infrastructure team, please follow these steps to request log streaming: + +### Step 1: Prepare your S3 bucket + +1. Create a dedicated bucket or path/prefix within your S3-compatible storage. +2. Grant the minimum required permissions to the credentials you will share with AdGuard. At a minimum, the credentials must have write permissions (`s3:PutObject`) on the designated path. + +### Step 2: Contact your account manager or AdGuard support team + +Reach out to your dedicated AdGuard account manager or contact AdGuard support team at `support@adguard-dns.io`, and provide the target account or organization for which logs should be streamed. + +### Step 3: Provide configuration details + +Once the request is approved, the support team will provide further instructions and request the specific configuration parameters required to establish the log stream. + +### Step 4: Wait for the log stream to be activated + +Once the log stream is activated, a `.healthcheck` file containing `ok` is automatically written to the destination bucket. If any connection or write errors occur during setup, you will be notified. No further action is required once the stream is enabled. + +## Log format and S3 object structure + +Logs are delivered as **minified JSON files containing an array of objects**, where each object within the array represents a single DNS query event. + +### Compression and encoding + +- **Encoding:** UTF-8 +- **Compression:** Gzip compression is mandatory and automatically applied to all exported log files. + +### S3 object layout and naming + +Log files are written to the S3-compatible bucket using a structured folder hierarchy and a specific timestamp-based naming convention to facilitate efficient partition-based querying and ingestion. + +- **Object prefix (Path):** `/logs/%Y/%m/%d/` (organized by Year, Month, and Day) +- **Filename pattern:** `%H-%M-%S-%3f.json.gz` (Hour-Minute-Second-Millisecond of the batch generation) + +**Example S3 object key:** + +`logs/2026/08/24/14-02-02-123.json.gz` + +### File schema structure + +Unlike JSON Lines (JSONL), the delivered file is a standard, single-line minified JSON array. + +**Example of the delivered minified file structure (uncompressed representation):** + +```json + +{"ASN":1234, +"AccountId":4432, +"Action":1, +"CategoryId":null, +"ClientCountry":null, +"DNSSEC":0, +"DeviceId":"54cff1db", +"DnsServerId":"b13fe9a2", +"DomainFQDN":"qwerty20.onlineteam.ru.", +"ElapsedMs":51, +"FilterListId":null, +"FilterRule":null, +"IpAddress":null, +"Protocol":8, +"RequestIdNum":65027, +"RequestType":1, +"ResponseCode":0, +"ResponseCountry":"RU", +"TimeAddedMs":1787671509268, +"TrackerId":null +} +``` + +## Fields reference {#fields-reference} + +The table below describes the schema for the exported DNS query logs. + +| Field | Type | Required | Description | Example | +| :---------------- | :------------ | :------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------- | +| `AccountId` | integer | No | Detected account ID, if any. | `1234` | +| `DnsServerId` | string | No | Detected profile ID, also known as DNS ID or DNS Server ID, if any. | `"prof1234"` | +| `DeviceId` | string | No | Detected device ID, if any. | `"dev1234"` | +| `ClientCountry` | string | No | Country of the client’s IP address as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo. | `"AU"` | +| `ResponseCountry` | string | No | Country of the first IP address in the response as an ISO 3166-1 alpha-2 code. Absent if it could not be detected. `XK` is used for Kosovo; `QN` means “Not Applicable” when the response type contains no IP address information. | `"US"` | +| `DomainFQDN` | string | Yes | Requested DNS resource name (FQDN). | `"example.com."` | +| `FilterListId` | string | No | ID of the first filter whose rules matched the query. Omitted if no rule matched. Reserved values include `adult_blocking`, `blocked_service`, `category`, `custom`, `general_safe_search`, `newly_registered_domains`, `safe_browsing`, and `youtube_safe_search`. | `"adguard_dns_filter"` | +| `FilterRule` | string | No | First rule that matched the query. For `blocked_service`, contains the blocked service ID. For `category`, contains the category ID. Omitted if no rule matched. | `"example.com^"` | +| `TimeAddedMs` | integer | Yes | Unix timestamp when the request was received, in milliseconds. | `1629974298000` | +| `ASN` | integer | No | Autonomous System Number (ASN) detected from the client’s IP address, if any. | `1234` | +| `ElapsedMs` | integer | Yes | Time elapsed since the beginning of request processing, in milliseconds. | `3` | +| `RequestType` | integer | Yes | Numeric DNS resource-record type of the query, for example `1` for an `A` record. | `1` | +| `RequestIdNum` | integer | Yes | Random unsigned 16-bit integer used to simplify deduplication when the old `u` field is not used. | `12345` | +| `Action` | integer | Yes | Filtering action: `0` unknown, `1` no filtering, `2` request blocked, `3` response blocked, `4` request allowed by allowlist, `5` response allowed by allowlist, `6` request or response modified/rewritten. | `2` | +| `DNSSEC` | integer | Yes | Whether the response was validated with DNSSEC: `0` = no, `1` = yes. | `1` | +| `Protocol` | integer | Yes | DNS protocol: `0` unknown, `3` DNS-over-HTTPS, `4` DNS-over-QUIC, `5` DNS-over-TLS, `8` Plain DNS, `9` DNSCrypt. | `3` | +| `ResponseCode` | integer | Yes | DNS response code (`RCODE`) sent to the client. | `0` | +| `IpAddress` | string | No | Client IP address. Omitted when IP logging is disabled for the corresponding profile. | `"1.2.3.4"` | +| `TrackerId` | string / null | Yes | Tracker ID found by matching the requested domain against the `dns-trackers` enrichment table. Set to `null` if no tracker is found. | `"google"` | +| `CategoryId` | string / null | Yes | Tracker category ID returned by the `dns-trackers` enrichment lookup. Set to `null` if no tracker is found. | `"search_engines"` | + +## Delivery guarantees and limitations {#delivery-guarantees-and-limitations} + +Understanding how logs are batched and delivered is critical for designing your SIEM ingestion pipeline. + +- **Batch-only delivery:** Logs are exported strictly in batches, not in real time. To keep the system stable and adapt to different traffic levels, both batch sizes and delivery intervals are flexible. Exact file sizes and upload times are not fixed and may vary as the system is optimized. +- **Expected latency and potential delays:** While we strive for minimal latency, there is an expected delivery latency. Occasional delays are possible due to high network traffic, system load, or processing queues. +- **At-least-once delivery:** Log delivery is guaranteed on an at-least-once basis. While this ensures that all events are successfully delivered, duplicate log entries may occasionally be written to the destination bucket (for example, during network retries or recovery from transient connection drops). Exactly-once delivery is not guaranteed. +- **Client-side deduplication required:** The client must be capable of deduplicating events within their SIEM or data lake. Deduplication should be handled using a combination of the event `timestamp` and other unique identifiers. +- **No order guarantees:** Due to the distributed nature of our global DNS infrastructure, the chronological order of events is not guaranteed. Events may arrive out of order within a single log file or across different batches. +- **Unreachable destination (retries or drops):** If your S3 endpoint or bucket becomes unreachable (e.g., due to expired credentials or network outages on your provider’s side), AdGuard DNS may attempt retries. However, depending on backend limits, log events generated during the outage might be dropped (skipped) to prevent buffer overflow. +- **No historical backfill:** Log streaming is strictly forward-looking. Exporting historical logs generated before the streaming feature was activated is not supported. + +## Security and privacy + +DNS query logs contain highly sensitive network and metadata. To ensure the safety of your organization’s data, please observe the following security principles: + +- **Sensitive DNS data:** Be aware that streamed logs can contain sensitive DNS metadata, including queried domains, device identifiers, client IP addresses, and geographic details of your clients. +- **Client responsibility:** The client is solely responsible for the overall security of their S3-compatible bucket, including configuring and maintaining secure bucket policies and access control lists (ACLs). +- **Restrict access:** We highly recommend restricting access to the bucket to the absolute minimum necessary. +- **Credential rotation:** Credentials (access keys and secrets) provided to AdGuard DNS for bucket access should be regularly rotated in accordance with your organization’s internal security policies. However, because changing keys on the cloud provider side immediately revokes AdGuard’s write permissions, new credentials must be updated in AdGuard at the same time to prevent log delivery disruption. +- **Dashboard logging settings impact:** If certain types of logging are disabled in your AdGuard DNS account settings, this will directly affect the schema of your exported logs. For example, if you disable specific device metadata logging, those fields will be omitted (or populated with null values) in the streamed JSON files. +- **No bypass of privacy settings:** AdGuard DNS strictly respects your configuration. Under no circumstances will AdGuard bypass, override, or circumvent your account’s privacy and data-anonymization settings when exporting events to your external storage. + +## How to ingest logs into SIEM + +Since AdGuard DNS streams query logs to S3-compatible storage, configuring the ingestion pipeline into your SIEM platform is handled entirely on your side. + +- **S3-compatible destination:** AdGuard DNS delivers raw log files directly to your designated S3 bucket, which serves as the central landing zone for your security data. +- **Custom ingestion pipeline:** You can connect and ingest these log files into your SIEM or analytics system using your own data pipelines, custom scripts, or ETL processes. +- **Standard S3 connectors:** For major platforms such as **Splunk**, **Microsoft Sentinel**, and **Elastic**, you typically utilize their respective native S3 connectors, inputs, or log collectors. +- **Infrastructure-dependent setup:** The exact configuration, index mapping, and parsing rules inside your SIEM depend heavily on your organization’s specific infrastructure, data schemas, and retention policies. + +## Troubleshooting + +This section details common integration issues you may encounter when setting up or running the query log stream, along with steps to resolve them. + +### Logs are not appearing in the bucket + +**Potential cause:** Configuration on the AdGuard side is not yet complete, or incorrect connection parameters were provided. + +**Resolution:** Verify that you received a confirmation email from your AdGuard account manager stating that the stream configuration is complete. Double-check all shared parameters (bucket name, endpoint, region). + +### Incorrect bucket permissions + +**Potential cause:** The credentials shared with AdGuard do not have sufficient permissions to write objects to the bucket. + +**Resolution:** Ensure that the AWS IAM policy (or your provider’s equivalent) associated with the provided access keys explicitly grants `s3:PutObject` permission for the target bucket and prefix. + +### S3 credentials expired + +**Potential cause:** The credentials have expired, or they were rotated/revoked in accordance with your organization’s internal security policies. + +**Resolution:** Generate a new set of access and secret keys, and share them securely with your AdGuard account manager to update your stream configuration. + +### Duplicates appeared in the log destination + +**Potential cause:** Network retries triggered by the “at-least-once” delivery model during transient network interruptions. + +**Resolution:** This is expected behavior in distributed logging pipelines. Configure deduplication rules in your SIEM or database using a combination of the `timestamp`, `domain`, and `device_id` (or other unique event identifiers). + +### Latency is higher than expected + +**Potential cause:** Temporary network congestion, system load, or buffering delays on the cloud provider’s side. + +**Resolution:** Check the operational status of your S3-compatible cloud provider. If log delivery delays consistently exceed your expected batch interval (e.g., more than 15–30 minutes), contact AdGuard support to check the status of our outbound delivery queues. + +### Missing fields in the logs + +**Potential cause:** Specific logging or privacy features (such as client IP logging or device metadata collection) are disabled in your AdGuard DNS dashboard settings. + +**Resolution:** Review your privacy and logging settings within the AdGuard DNS dashboard. The log streaming export strictly respects these settings and will not bypass your data-minimization preferences. + +### Enterprise status changed + +**Potential cause:** Your Enterprise subscription has expired, was cancelled, or your account was downgraded. + +**Resolution:** Log streaming is deactivated automatically if the account loses Enterprise status. Contact your AdGuard account manager to restore your subscription and reactivate the stream. + +### SIEM fails to parse or split the JSON array + +**Potential Cause:** Many S3 log collectors expect Newline Delimited JSON (NDJSON/JSONL) by default. Since the exported logs are formatted as a minified JSON array (`[...]`), the collector may fail to parse the file or ingest the entire array as a single, massive log event instead of splitting it into individual query records. + +**Resolution:** Configure the S3 connector, log shipper, or SIEM parser to handle standard JSON arrays. The ingestion pipeline must be set to unpack the array and split its elements into separate log entries before indexing. + +### Compressed files do not decompress + +**Potential cause:** The compression format (e.g., `.gz`) used during export is either unsupported or misconfigured in your SIEM’s ingestion connector. + +**Resolution:** Verify the decompression settings on your SIEM connector (e.g., ensure automatic gzip decompression is enabled for S3 object retrieval). + +## 常見問答集 + +### Can logs be streamed directly to Splunk or Microsoft Sentinel? + +No. In the current MVP version, direct streaming to SIEM endpoints or APIs (such as Splunk HEC) is not supported. Logs must be written to an S3-compatible bucket first, which the SIEM can then monitor and ingest from using standard S3 connectors. + +### Can storage options other than S3 be used? + +No. Currently, only S3-compatible storage is supported. Standard options include Amazon S3 or compatible offerings from other cloud providers (e.g., Cloudflare R2, Backblaze B2, Wasabi, or MinIO). Native integration with other storage types (such as direct Azure Blob or SFTP) is not available at this time. + +### Is it possible to retrieve historical logs? + +No. Log streaming is strictly forward-looking. Only DNS query events generated _after_ the streaming feature has been successfully activated and configured will be exported. Historical backfill of logs is not supported. + +### How quickly are logs delivered? + +Logs are delivered in compressed batches rather than in real-time. For more details on batching intervals and delivery mechanics, refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section. + +### Is the delivery of every single event guaranteed? + +Yes, under normal operating conditions. However, if the destination bucket becomes unreachable, log events may eventually be dropped once the retry buffer limit is exceeded. Refer to the [Delivery guarantees and limitations](#delivery-guarantees-and-limitations) section for details. + +### Are duplicate events possible in the destination? + +Yes. Under the “at-least-once” delivery model, network retries triggered by transient outages can cause duplicate log events to be written to the bucket. The ingestion pipeline or SIEM must be configured to handle deduplication. + +### What fields are included in the logs? + +The logs include essential DNS query fields such as `TimeAddedMs` (timestamp), `DomainFQDN`, `RequestType`, `Action`, and `ClientCountry`. For the full list of fields and data types, refer to the [Fields reference](#fields-reference) section. Account privacy settings directly affect these logs; sensitive fields (such as `IpAddress`) will be omitted or set to `null` if logging is disabled in the dashboard. + +### What happens if the Enterprise status is lost? + +Log streaming is strictly an Enterprise-tier feature. If the account is no longer on an Enterprise plan or the subscription lapses, the streaming service will be deactivated automatically. + +### Can log streaming be deactivated? + +Yes. The log stream can be deactivated at any time upon request. To do so, please contact the dedicated AdGuard account manager or reach out to the AdGuard support team at `support@adguard-dns.io`. + +### Can multiple S3 streaming destinations be configured? + +No. The current version only supports configuring a single S3-compatible streaming destination per Enterprise organization. diff --git a/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md b/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md index 90ecc6874..3367affbe 100644 --- a/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md +++ b/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/query-log.md @@ -3,25 +3,25 @@ title: Query log sidebar_position: 5 --- -## What is Query log +## What is Query log? -Query log is a useful tool for working with AdGuard DNS. +_Query log_ is a useful tool for working with AdGuard DNS. It allows you to view all requests made by your devices during the selected time period and sort requests by status, type, company, device, country. ## How to use it -Here’s what you can see and what you can do in the _Query log_. +Here’s what you can see and what you can do in _Query log_. ### Detailed information on requests -![Requests info \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) +![Requests info \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/detailed_info.png) ### Blocking and unblocking domains Requests can be blocked and unblocked without leaving the log, using the available tools. -![Unblock domain \*border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) +![Unblock domain \*mobile_border](https://cdn.adtidy.org/content/kb/dns/private/new_dns/statistics/unblock_domain.png) ### Sorting requests diff --git a/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md b/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md index b9047787e..4281c19bb 100644 --- a/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md +++ b/i18n/zh-TW/docusaurus-plugin-content-docs/current/private-dns/statistics-and-log/statistics-and-log.md @@ -11,3 +11,4 @@ AdGuard DNS provides a wide range of useful tools for monitoring queries: - [Traffic destination](/private-dns/statistics-and-log/traffic-destination.md) - [Companies](/private-dns/statistics-and-log/companies.md) - [Query log](/private-dns/statistics-and-log/query-log.md) +- [Query log streaming](/private-dns/statistics-and-log/query-log-streaming.md)