Skip to main content
Tools Reference

DNSFilter Tools

Written By Christopher Scaminaci

Last updated 7 days ago

DNSFilter Tools

dnsfilter_ · 238 tools · Free 151 · Pro 87 Protective DNS for MSPs. The credential is an API token sent as the entire Authorization value with no Bearer prefix - adding a scheme fails every call. The host is fixed and global. Paths carry their own version: v1 and v2 coexist on one host, sometimes for the same resource. Paging is page[number] with page[size] on 43 operations - a plain page parameter is ignored silently - with a page cap of 1000 applied here because the vendor declares no maximum. Filter parameters come in three shapes: comma-separated strings, repeated array parameters, and bracket filters carrying a value and an operator. A 403 is not declared anywhere in this API, so permission failures arrive as 401 and a 401 is not proof of a bad token.

All connector tools · DNSFilter setup guide

DNSFilter tool groups

Traffic Reports & Query Logs

ToolPlanAccessSummary
dnsfilter_traffic_qpsFreeRead-onlyQuery rate (queries per second) over a time window — the load view, as opposed to the raw counts total_requests returns.
dnsfilter_traffic_qps_active_agentsFreeRead-onlyRoaming client agents actively sending DNS queries in the window, with their query rate.
dnsfilter_traffic_qps_active_collectionsFreeRead-onlyCollections actively sending DNS queries in the window, with their query rate.
dnsfilter_traffic_qps_active_organizationsFreeRead-onlyOrganizations actively sending DNS queries in the window, with their query rate.
dnsfilter_traffic_qps_active_usersFreeRead-onlyUsers actively sending DNS queries in the window, with their query rate.
dnsfilter_traffic_query_logsFreeRead-onlySearch the raw DNS query log — every individual lookup, with the domain asked for and whether it was allowed or blocked.
dnsfilter_traffic_top_agentsFreeRead-onlyThe busiest roaming client agents in the window, ranked by request volume.
dnsfilter_traffic_top_application_categoriesFreeRead-onlyThe most-used application categories in the window, ranked.
dnsfilter_traffic_top_categoriesFreeRead-onlyThe most-requested content categories in the window, ranked.
dnsfilter_traffic_top_collectionsFreeRead-onlyThe busiest collections in the window, ranked by request volume.
dnsfilter_traffic_top_domainsFreeRead-onlyThe most-requested domains in the window, ranked.
dnsfilter_traffic_top_networksFreeRead-onlyThe busiest networks in the window, ranked by request volume.
dnsfilter_traffic_top_organizationsFreeRead-onlyThe busiest organizations in the window, ranked by request volume.
dnsfilter_traffic_top_organizations_requestsFreeRead-onlyOrganizations ranked by request count within a single parent organization's scope.
dnsfilter_traffic_top_usersFreeRead-onlyThe busiest users in the window, ranked by request volume.
dnsfilter_traffic_total_applications_agents_statsFreeRead-onlyApplication usage statistics over a time window, attributed to roaming client agents.
dnsfilter_traffic_total_applications_collections_statsFreeRead-onlyApplication usage statistics over a time window, attributed to collections.
dnsfilter_traffic_total_applications_networks_statsFreeRead-onlyApplication usage statistics over a time window, attributed to networks.
dnsfilter_traffic_total_applications_organizations_statsFreeRead-onlyApplication usage statistics over a time window, attributed to organizations.
dnsfilter_traffic_total_applications_statsFreeRead-onlyApplication usage statistics over a time window — which SaaS and web applications are being reached.
dnsfilter_traffic_total_applications_users_statsFreeRead-onlyApplication usage statistics over a time window, attributed to users.
dnsfilter_traffic_total_categoriesFreeRead-onlyDNS traffic broken down by content category over a time window — what people are browsing, grouped the way the filtering policy groups it.
dnsfilter_traffic_total_categories_agentsFreeRead-onlyContent-category traffic over a time window, attributed to roaming client agents.
dnsfilter_traffic_total_categories_collectionsFreeRead-onlyContent-category traffic over a time window, attributed to collections.
dnsfilter_traffic_total_categories_organizationsFreeRead-onlyContent-category traffic over a time window, attributed to organizations.
dnsfilter_traffic_total_categories_usersFreeRead-onlyContent-category traffic over a time window, attributed to users.
dnsfilter_traffic_total_category_statsFreeRead-onlySummary statistics for content categories over a time window.
dnsfilter_traffic_total_client_statsFreeRead-onlySummary client statistics over a time window.
dnsfilter_traffic_total_collectionsFreeRead-onlyDNS traffic broken down by collection over a time window.
dnsfilter_traffic_total_collections_agentsFreeRead-onlyCollection traffic over a time window, attributed to roaming client agents.
dnsfilter_traffic_total_collections_organizationsFreeRead-onlyCollection traffic over a time window, attributed to organizations.
dnsfilter_traffic_total_collections_usersFreeRead-onlyCollection traffic over a time window, attributed to users.
dnsfilter_traffic_total_deploymentsFreeRead-onlyCurrent deployment count for an organization.
dnsfilter_traffic_total_domain_requestsFreeRead-onlyRequest totals for one domain over a time window.
dnsfilter_traffic_total_domain_statsFreeRead-onlySummary statistics for one domain over a time window.
dnsfilter_traffic_total_domainsFreeRead-onlyDNS traffic broken down by domain over a time window.
dnsfilter_traffic_total_domains_collectionsFreeRead-onlyDomain traffic over a time window, attributed to collections.
dnsfilter_traffic_total_domains_organizationsFreeRead-onlyDomain traffic over a time window, attributed to organizations.
dnsfilter_traffic_total_domains_usersFreeRead-onlyDomain traffic over a time window, attributed to users.
dnsfilter_traffic_total_organizations_requestsFreeRead-onlyRequest totals for organizations within a parent organization's scope.
dnsfilter_traffic_total_organizations_statsFreeRead-onlySummary statistics for a single organization over a time window.
dnsfilter_traffic_total_requestsFreeRead-onlyTotal DNS requests over a time window, returned as a time series for charting.
dnsfilter_traffic_total_requests_agentsFreeRead-onlyTotal DNS requests over a time window, attributed to roaming client agents.
dnsfilter_traffic_total_requests_collectionsFreeRead-onlyTotal DNS requests over a time window, attributed to collections.
dnsfilter_traffic_total_requests_geoFreeRead-onlyDNS request volume broken down by geography, for the requested number of top locations.
dnsfilter_traffic_total_requests_organizationsFreeRead-onlyTotal DNS requests over a time window, attributed to organizations.
dnsfilter_traffic_total_requests_usersFreeRead-onlyTotal DNS requests over a time window, attributed to users.
dnsfilter_traffic_total_roaming_clientsFreeRead-onlyCurrent roaming client count for an organization.
dnsfilter_traffic_total_threatsFreeRead-onlyTotal threat lookups blocked over a time window, as a time series.
dnsfilter_traffic_total_threats_agentsFreeRead-onlyThreat lookups blocked over a time window, attributed to roaming client agents — use it to find the specific machines generating threat traffic.
dnsfilter_traffic_total_threats_collectionsFreeRead-onlyThreat lookups blocked over a time window, attributed to collections.
dnsfilter_traffic_total_threats_organizationsFreeRead-onlyThreat lookups blocked over a time window, attributed to organizations — the report that answers which client is most at risk.
dnsfilter_traffic_total_threats_usersFreeRead-onlyThreat lookups blocked over a time window, attributed to users.

[DNSFilter] Query rate (queries per second) over a time window — the load view, as opposed to the raw counts total_requests returns. Set showIndividualNetworks to break it out per network. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualNetworksbooleannonullOptional. Set true to break the totals out per network instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Roaming client agents actively sending DNS queries in the window, with their query rate. Use it to confirm which machines are reporting in. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Collections actively sending DNS queries in the window, with their query rate. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Organizations actively sending DNS queries in the window, with their query rate. Use it to see which clients are actually live. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Users actively sending DNS queries in the window, with their query rate. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Search the raw DNS query log — every individual lookup, with the domain asked for and whether it was allowed or blocked. This is the investigation tool: use it to answer what a specific machine resolved before it got infected, or what a user was reaching at a particular time. Narrow it with a time window plus any combination of domain, category, network, agent or user filters, then page through the results. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdstringnonullOptional. A single roaming client agent UUID to scope the search to.
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
applicationCategoryIdsstringnonullOptional. Comma-separated application category IDs. Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
categoryIdsstringnonullOptional. Comma-separated content category IDs. Defaults to all. Discover IDs with dnsfilter_list_categories.
collectionIdintegernonullOptional. A single collection ID to scope the search to.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
domainstringnonullOptional. Restrict the report to a single domain.
excludeCategoryIdsstringnonullOptional. Comma-separated content category IDs to EXCLUDE. Applied independently of categoryIds — a row is dropped if it matches at least one of these.
fqdnstringnonullOptional. Restrict the report to a single fully-qualified domain name.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdintegernonullOptional. A single network ID to scope the search to.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdintegernonullOptional. A single organization ID to scope the report to. Discover IDs with dnsfilter_list_organizations.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
policyIdsstringnonullOptional. Comma-separated policy IDs to restrict the search to.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
questionTypestringnonullOptional. Restrict to a single DNS question type (for example A or AAAA).
resultstringnonullOptional. Restrict to a single lookup result — how DNSFilter answered the query.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
userIdintegernonullOptional. A single local user ID to scope the search to.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] The busiest roaming client agents in the window, ranked by request volume. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] The most-used application categories in the window, ranked. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] The most-requested content categories in the window, ranked. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] The busiest collections in the window, ranked by request volume. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] The most-requested domains in the window, ranked. The report to reach for when asked what a network or machine has been visiting. Narrow with domain, fqdn or categoryIds. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
categoryIdsstringnonullOptional. Comma-separated content category IDs. Defaults to all. Discover IDs with dnsfilter_list_categories.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
domainstringnonullOptional. Restrict the report to a single domain.
fqdnstringnonullOptional. Restrict the report to a single fully-qualified domain name.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] The busiest networks in the window, ranked by request volume. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] The busiest organizations in the window, ranked by request volume. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Organizations ranked by request count within a single parent organization's scope. Takes a singular organizationId rather than the plural filter the other reports use. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
organizationIdintegernonullOptional. A single organization ID to scope the report to. Discover IDs with dnsfilter_list_organizations.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.

[DNSFilter] The busiest users in the window, ranked by request volume. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Application usage statistics over a time window, attributed to roaming client agents. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationCategoryIdsstringnonullOptional. Comma-separated application category IDs. Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Application usage statistics over a time window, attributed to collections. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationCategoryIdsstringnonullOptional. Comma-separated application category IDs. Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Application usage statistics over a time window, attributed to networks. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationCategoryIdsstringnonullOptional. Comma-separated application category IDs. Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Application usage statistics over a time window, attributed to organizations. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationCategoryIdsstringnonullOptional. Comma-separated application category IDs. Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Application usage statistics over a time window — which SaaS and web applications are being reached. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationCategoryIdsstringnonullOptional. Comma-separated application category IDs. Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Application usage statistics over a time window, attributed to users. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationCategoryIdsstringnonullOptional. Comma-separated application category IDs. Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] DNS traffic broken down by content category over a time window — what people are browsing, grouped the way the filtering policy groups it. Set showIndividualNetworks to break it out per network. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualNetworksbooleannonullOptional. Set true to break the totals out per network instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Content-category traffic over a time window, attributed to roaming client agents. Set showIndividualAgents for one series per agent. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualAgentsbooleannonullOptional. Set true to break the totals out per roaming client agent instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Content-category traffic over a time window, attributed to collections. Set showIndividualCollections for one series per collection. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualCollectionsbooleannonullOptional. Set true to break the totals out per collection instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Content-category traffic over a time window, attributed to organizations. Set showIndividualOrganizations for one series per organization. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualOrganizationsbooleannonullOptional. Set true to break the totals out per organization instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Content-category traffic over a time window, attributed to users. Set showIndividualUsers for one series per user. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualUsersbooleannonullOptional. Set true to break the totals out per user instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Summary statistics for content categories over a time window. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
categoryIdsstringnonullOptional. Comma-separated content category IDs. Defaults to all. Discover IDs with dnsfilter_list_categories.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdintegernonullOptional. A single organization ID to scope the report to. Discover IDs with dnsfilter_list_organizations.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.

[DNSFilter] Summary client statistics over a time window. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdintegernonullOptional. A single organization ID to scope the report to. Discover IDs with dnsfilter_list_organizations.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.

[DNSFilter] DNS traffic broken down by collection over a time window. Set showIndividualNetworks to break it out per network. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualNetworksbooleannonullOptional. Set true to break the totals out per network instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Collection traffic over a time window, attributed to roaming client agents. Set showIndividualAgents for one series per agent. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualAgentsbooleannonullOptional. Set true to break the totals out per roaming client agent instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Collection traffic over a time window, attributed to organizations. Set showIndividualOrganizations for one series per organization. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualOrganizationsbooleannonullOptional. Set true to break the totals out per organization instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Collection traffic over a time window, attributed to users. Set showIndividualUsers for one series per user. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualUsersbooleannonullOptional. Set true to break the totals out per user instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Current deployment count for an organization. A point-in-time count, so it takes no time window. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdintegernonullOptional. A single organization ID to scope the report to. Discover IDs with dnsfilter_list_organizations.

[DNSFilter] Request totals for one domain over a time window. Unlike the domain statistics report this takes no fqdn filter. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
domainstringnonullOptional. Restrict the report to a single domain.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdintegernonullOptional. A single organization ID to scope the report to. Discover IDs with dnsfilter_list_organizations.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.

[DNSFilter] Summary statistics for one domain over a time window. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
domainstringnonullOptional. Restrict the report to a single domain.
fqdnstringnonullOptional. Restrict the report to a single fully-qualified domain name.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdintegernonullOptional. A single organization ID to scope the report to. Discover IDs with dnsfilter_list_organizations.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.

[DNSFilter] DNS traffic broken down by domain over a time window. Narrow it with the domain or categoryIds filters. Set showIndividualNetworks to break it out per network. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
categoryIdsstringnonullOptional. Comma-separated content category IDs. Defaults to all. Discover IDs with dnsfilter_list_categories.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
domainstringnonullOptional. Restrict the report to a single domain.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualNetworksbooleannonullOptional. Set true to break the totals out per network instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Domain traffic over a time window, attributed to collections. Set showIndividualCollections for one series per collection. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
categoryIdsstringnonullOptional. Comma-separated content category IDs. Defaults to all. Discover IDs with dnsfilter_list_categories.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
domainstringnonullOptional. Restrict the report to a single domain.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualCollectionsbooleannonullOptional. Set true to break the totals out per collection instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Domain traffic over a time window, attributed to organizations. Set showIndividualOrganizations for one series per organization. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
categoryIdsstringnonullOptional. Comma-separated content category IDs. Defaults to all. Discover IDs with dnsfilter_list_categories.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
domainstringnonullOptional. Restrict the report to a single domain.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualOrganizationsbooleannonullOptional. Set true to break the totals out per organization instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Domain traffic over a time window, attributed to users. Set showIndividualUsers for one series per user. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
categoryIdsstringnonullOptional. Comma-separated content category IDs. Defaults to all. Discover IDs with dnsfilter_list_categories.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
domainstringnonullOptional. Restrict the report to a single domain.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualUsersbooleannonullOptional. Set true to break the totals out per user instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Request totals for organizations within a parent organization's scope. The one report that takes BOTH the singular organizationId scope and the plural organizationIds filter. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
categoryIdsstringnonullOptional. Comma-separated content category IDs. Defaults to all. Discover IDs with dnsfilter_list_categories.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
domainstringnonullOptional. Restrict the report to a single domain.
fqdnstringnonullOptional. Restrict the report to a single fully-qualified domain name.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdintegernonullOptional. A single organization ID to scope the report to. Discover IDs with dnsfilter_list_organizations.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Summary statistics for a single organization over a time window. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationCategoryIdsstringnonullOptional. Comma-separated application category IDs. Defaults to all.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
namestringnonullOptional. Name search term — narrows the leaderboard to entries whose name matches.
organizationIdintegernonullOptional. A single organization ID to scope the report to. Discover IDs with dnsfilter_list_organizations.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Total DNS requests over a time window, returned as a time series for charting. The headline volume report — use it to see overall query load and how it moves. Set showIndividualNetworks to break the series out per network. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualNetworksbooleannonullOptional. Set true to break the totals out per network instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Total DNS requests over a time window, attributed to roaming client agents. Set showIndividualAgents to return one series per agent rather than a combined total. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualAgentsbooleannonullOptional. Set true to break the totals out per roaming client agent instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Total DNS requests over a time window, attributed to collections. Set showIndividualCollections to return one series per collection rather than a combined total. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualCollectionsbooleannonullOptional. Set true to break the totals out per collection instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] DNS request volume broken down by geography, for the requested number of top locations. Unlike every other traffic report this one REQUIRES a limit. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
limitintegerno10Required. How many locations to return.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.

[DNSFilter] Total DNS requests over a time window, attributed to organizations. Set showIndividualOrganizations to return one series per organization rather than a combined total. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualOrganizationsbooleannonullOptional. Set true to break the totals out per organization instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Total DNS requests over a time window, attributed to users. Set showIndividualUsers to return one series per user rather than a combined total. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
natIpsstringnonullOptional. Comma-separated NAT IP addresses. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
securityReportbooleannonullOptional. Set true to count only security (threat) traffic rather than all DNS traffic.
showIndividualUsersbooleannonullOptional. Set true to break the totals out per user instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Current roaming client count for an organization. A point-in-time count, so it takes neither a time window nor a network filter. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
mspIdintegernonullOptional. MSP ID to scope the report to, when the token's account manages several.
organizationIdintegernonullOptional. A single organization ID to scope the report to. Discover IDs with dnsfilter_list_organizations.

[DNSFilter] Total threat lookups blocked over a time window, as a time series. Use it to show security value and spot an infection spike. This report is already scoped to security traffic, so it takes no securityReport flag. Set showIndividualNetworks to break it out per network. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
showIndividualNetworksbooleannonullOptional. Set true to break the totals out per network instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Threat lookups blocked over a time window, attributed to roaming client agents — use it to find the specific machines generating threat traffic. Set showIndividualAgents for one series per agent. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
showIndividualAgentsbooleannonullOptional. Set true to break the totals out per roaming client agent instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Threat lookups blocked over a time window, attributed to collections. Set showIndividualCollections for one series per collection. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
showIndividualCollectionsbooleannonullOptional. Set true to break the totals out per collection instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Threat lookups blocked over a time window, attributed to organizations — the report that answers which client is most at risk. Set showIndividualOrganizations for one series per organization. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
showIndividualOrganizationsbooleannonullOptional. Set true to break the totals out per organization instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

[DNSFilter] Threat lookups blocked over a time window, attributed to users. Set showIndividualUsers for one series per user. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentIdsstringnonullOptional. Comma-separated roaming client agent UUIDs. Defaults to all. Discover IDs with dnsfilter_list_user_agents.
agentTypesstringnonullOptional. Comma-separated agent types to include (windows, macos, ios, android, chrome). Defaults to all.
applicationIdsstringnonullOptional. Comma-separated application IDs. Defaults to all. Discover IDs with dnsfilter_list_applications.
bucketSizestringnonullOptional. Granularity of the returned time buckets — how finely the window is sliced for charting.
collectionIdsstringnonullOptional. Comma-separated collection IDs. Defaults to all.
fromstringnonullOptional. Start of the reporting window, as an ISO 8601 timestamp or date.
macAddressesstringnonullOptional. Comma-separated MAC addresses, written without colons. Defaults to all.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all. Discover IDs with dnsfilter_list_networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs to report on. Defaults to the token's own organization. Discover IDs with dnsfilter_list_organizations.
privateIpstringnonullOptional. Restrict to a single private (LAN) IP address.
privateIpFromstringnonullOptional. Start of a private IP address range.
privateIpTostringnonullOptional. End of a private IP address range.
showIndividualUsersbooleannonullOptional. Set true to break the totals out per user instead of returning one combined series.
sourcestringnonullOptional. Restrict to a single traffic source.
tostringnonullOptional. End of the reporting window, as an ISO 8601 timestamp or date.
typestringnonullOptional. Restrict to a single request type.
userIdsstringnonullOptional. Comma-separated local user IDs. Defaults to all.

API Keys

ToolPlanAccessSummary
dnsfilter_create_api_keyProWriteMint a new DNSFilter API key.
dnsfilter_delete_api_keyProDestructivePermanently delete a DNSFilter API key by ID (from dnsfilter_list_api_keys).
dnsfilter_get_api_keyFreeRead-onlyGet one DNSFilter API key by ID (from dnsfilter_list_api_keys).
dnsfilter_list_api_keysFreeRead-onlyList the DNSFilter API keys belonging to the account this connection authenticates as.
dnsfilter_revoke_api_keyProDestructiveRevoke a DNSFilter API key by ID (from dnsfilter_list_api_keys), invalidating the token while leaving the record in place.

[DNSFilter] Mint a new DNSFilter API key. Body (fieldsJson) is a JSON object; fields: name (label for the key), expiry (when it stops working). Not destructive — it only adds a credential and changes nothing that already exists. The response carries the token value, and this is the ONLY time DNSFilter returns it: afterwards only the last four characters are readable. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: name (label for the key), expiry (when the key stops working).

[DNSFilter] Permanently delete a DNSFilter API key by ID (from dnsfilter_list_api_keys). Destructive and irreversible — the key stops authenticating immediately and its token value cannot be recovered or recreated. Anything built on that key breaks, INCLUDING this StackJack connection if the id belongs to the key StackJack authenticates with. Confirm which key you are removing with dnsfilter_get_api_key first. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe API key ID to delete (from dnsfilter_list_api_keys).

[DNSFilter] Get one DNSFilter API key by ID (from dnsfilter_list_api_keys). Returns the key's metadata — name, expiry, last four characters, scope — never the token value, which DNSFilter shows only once at creation. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe API key ID (from dnsfilter_list_api_keys).

[DNSFilter] List the DNSFilter API keys belonging to the account this connection authenticates as. Scoped to the token's OWN user, not the whole organization — an empty result does not prove the organization has no keys. Filter by name, by the last four characters of the token, by expiry state or by organization. Token values are never returned, only metadata. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
expiredbooleannonullOptional. True returns only expired keys, false only unexpired ones. Omit for both.
idintegernonullOptional. A single API key ID to look up.
lastFourstringnonullOptional. The last four characters of the key's token, which is how DNSFilter's UI identifies a key you can no longer read in full.
namestringnonullOptional. Filter by the key's name.
organizationIdintegernonullOptional. Restrict to keys scoped to this organization ID.

[DNSFilter] Revoke a DNSFilter API key by ID (from dnsfilter_list_api_keys), invalidating the token while leaving the record in place. Destructive and irreversible — the token stops authenticating immediately and cannot be un-revoked; a replacement must be minted with dnsfilter_create_api_key. Every integration using that token breaks, INCLUDING this StackJack connection if the id belongs to the key StackJack authenticates with. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe API key ID to revoke (from dnsfilter_list_api_keys).

Block Pages

ToolPlanAccessSummary
dnsfilter_create_block_pageProWriteCreate a block page — the branded page end users see when DNSFilter blocks a lookup.
dnsfilter_delete_block_pageProDestructivePermanently delete a block page by ID (from dnsfilter_list_block_pages).
dnsfilter_get_block_pageFreeRead-onlyGet one block page by ID (from dnsfilter_list_block_pages), including its branding fields and, by default, the related records that reference it.
dnsfilter_list_all_block_pagesFreeRead-onlyList ALL block pages the account can see, DNSFilter's wider counterpart to dnsfilter_list_block_pages.
dnsfilter_list_block_pagesFreeRead-onlyList the block pages available to the account this connection authenticates as — the branded pages DNSFilter serves when it blocks a lookup.
dnsfilter_update_block_pageProWriteUpdate a block page by ID (from dnsfilter_list_block_pages).

[DNSFilter] Create a block page — the branded page end users see when DNSFilter blocks a lookup. Not destructive: it adds a new page and changes nothing that already exists, and nothing sees it until a policy is pointed at it. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: name, organization_id, block_org_name (the company name shown to the blocked user), block_email_addr (the contact address shown on the page), block_logo_uuid (an uploaded logo asset).

[DNSFilter] Permanently delete a block page by ID (from dnsfilter_list_block_pages). Destructive and irreversible — the branding is gone and any policy still pointing at this page falls back to whatever DNSFilter serves by default, which changes what real users see at block time. Check what references it with dnsfilter_get_block_page first. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe block page ID to delete (from dnsfilter_list_block_pages).

[DNSFilter] Get one block page by ID (from dnsfilter_list_block_pages), including its branding fields and, by default, the related records that reference it. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe block page ID (from dnsfilter_list_block_pages).
includeRelationshipsbooleannonullOptional. Whether to include related records in the response. DNSFilter defaults this to true, so pass false for a smaller payload.

[DNSFilter] List ALL block pages the account can see, DNSFilter's wider counterpart to dnsfilter_list_block_pages. The vendor documents the two only as "extant" versus "all" and does not say what it excludes from the narrower read, so prefer this one when auditing coverage and the other for the working set. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
organizationIdintegernonullOptional. Restrict to block pages belonging to this organization ID.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] List the block pages available to the account this connection authenticates as — the branded pages DNSFilter serves when it blocks a lookup. Paginated. DNSFilter calls this the "extant" list and offers a separate wider read, dnsfilter_list_all_block_pages; when a page you expect is missing, try that one before concluding it does not exist. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
organizationIdintegernonullOptional. Restrict to block pages belonging to this organization ID.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] Update a block page by ID (from dnsfilter_list_block_pages). Send only the fields you want changed. Not destructive: it edits one record's own fields, affects no other object, and any field can be set back by a second update — but the change IS live immediately for every user any policy serves this page to, so confirm the id with dnsfilter_get_block_page first. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: name, organization_id, block_org_name (the company name shown to the blocked user), block_email_addr (the contact address shown on the page), block_logo_uuid (an uploaded logo asset).
idintegeryesThe block page ID to update (from dnsfilter_list_block_pages).

Organizations & Users

ToolPlanAccessSummary
dnsfilter_add_collection_userProWriteAdd an existing user to a collection.
dnsfilter_bulk_update_organizationsProDestructiveApply settings to MANY organizations in one call — agent auto-update, uninstall notifications and their recipient list, VPN settings.
dnsfilter_cancel_organizationProDestructiveSet an organization to "Canceled".
dnsfilter_change_user_passwordProDestructiveChange the password of the currently authenticated DNSFilter user — the account behind this connection, NOT an arbitrary user.
dnsfilter_create_organizationProWriteCreate an organization (for an MSP, a new customer tenant).
dnsfilter_create_organization_userProWriteGrant a person access to an organization by email, creating the DNSFilter user if it does not already exist.
dnsfilter_delete_organizationProDestructiveDelete an MSP customer organization by ID.
dnsfilter_delete_organization_userProDestructiveRemove a person's access to an organization.
dnsfilter_get_collection_userFreeRead-onlyGet one user's details within a collection.
dnsfilter_get_organizationFreeRead-onlyGet one organization by ID (from dnsfilter_list_organizations), optionally with its current MRR.
dnsfilter_get_organization_settingsFreeRead-onlyRead organization-level settings — the account-wide toggles (agent auto-update, uninstall notifications, VPN settings) that dnsfilter_bulk_update_organizations writes.
dnsfilter_get_organization_userFreeRead-onlyGet one organization user with their role and permission set.
dnsfilter_get_userFreeRead-onlyGet one DNSFilter console user by ID.
dnsfilter_list_all_organizationsFreeRead-onlyList ALL organizations the account can see, DNSFilter's wider counterpart to dnsfilter_list_organizations.
dnsfilter_list_all_usersFreeRead-onlyList ALL DNSFilter console users, the wider counterpart to dnsfilter_list_users.
dnsfilter_list_collection_usersFreeRead-onlyList the users belonging to a collection — the grouping DNSFilter uses to scope policies and reporting to a set of people.
dnsfilter_list_organization_usersFreeRead-onlyList the DNSFilter console users who have access to an organization, with their roles.
dnsfilter_list_organizationsFreeRead-onlyList the organizations this account can see — for an MSP, the customer tenants.
dnsfilter_list_usersFreeRead-onlyList the DNSFilter console users visible to this account.
dnsfilter_promote_organization_to_mspProDestructivePromote an organization to MSP status, letting it own sub-organizations.
dnsfilter_remove_collection_userProWriteRemove a user from a collection.
dnsfilter_resend_organization_user_inviteProDestructiveResend the DNSFilter invitation email for a user in an organization.
dnsfilter_update_organizationProWriteUpdate one organization by ID (from dnsfilter_list_organizations).
dnsfilter_update_organization_userProWriteUpdate an organization user's details, role or permissions.

[DNSFilter] Add an existing user to a collection. Not destructive: it is a reversible membership change that dnsfilter_remove_collection_user undoes exactly, and it creates nothing. It does take effect on live filtering, because policies scoped to the collection now apply to this user. Body: {"collection_id": N, "id": N}. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
collectionIdintegeryesThe collection ID to add the user to.
fieldsJsonstringyesJSON object body. Fields: collection_id, id (the user to add).

[DNSFilter] Apply settings to MANY organizations in one call — agent auto-update, uninstall notifications and their recipient list, VPN settings. Destructive: the target set is whatever organization_ids (or an msp_id minus exclude_organization_ids) resolves to, which can be every customer under an MSP, and the previous per-organization values are overwritten with no record of what they were. Read the current state with dnsfilter_get_organization_settings first. Body fields: organization_ids, msp_id, exclude_organization_ids, send_uninstall_notifications_to_admin_users, user_agent_uninstall_notification, user_agent_uninstall_notification_recipient_emails, user_agents_auto_update, vpn_settings_organization_attributes. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: organization_ids (array), msp_id, exclude_organization_ids (array), send_uninstall_notifications_to_admin_users, user_agent_uninstall_notification, user_agent_uninstall_notification_recipient_emails (array), user_agents_auto_update, vpn_settings_organization_attributes.

[DNSFilter] Set an organization to "Canceled". Destructive: it ends the customer's service state in DNSFilter and has billing consequences with the vendor that StackJack cannot see or undo. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe organization ID to cancel (from dnsfilter_list_organizations).

[DNSFilter] Change the password of the currently authenticated DNSFilter user — the account behind this connection, NOT an arbitrary user. Destructive: it immediately invalidates the old password for a real person, may sign their sessions out, and cannot be undone without the new value. Body: {"new_password": "..."}. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Field: new_password.

[DNSFilter] Create an organization (for an MSP, a new customer tenant). Not destructive: it adds a tenant and changes nothing that already exists. Note this may consume licence quantity against the parent MSP's plan depending on the sku and quantity you send. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in an "organization" key: {"organization": }. Fields: name, billing_contact_name, billing_contact_phone, billing_contact_email, address, managed_by_msp_id (the parent MSP), unique_id, sku, quantity, privacy_mode (inherit | standard | identify_devices | maximum), enable_cybersight, vpn_settings_organization_attributes.

[DNSFilter] Grant a person access to an organization by email, creating the DNSFilter user if it does not already exist. Not destructive — it adds access and alters nothing existing — but it DOES email an invitation to a real person, and the role plus organization_permission_ids you send decide what they can change. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "user" key: {"user": }. Fields: email, first_name, last_name, phone, role, organization_permission_ids (array of permission IDs), is_include_only_list.
organizationIdintegeryesThe organization ID (from dnsfilter_list_organizations).

[DNSFilter] Delete an MSP customer organization by ID. Destructive and irreversible — it removes the tenant along with its networks, policies and roaming-client enrolment, and DNS filtering stops for everyone in it. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
clearSubscriptionInfobooleannonullOptional. Also clear the subscription information tied to the customer. Defaults to false.
idintegeryesThe organization ID to delete (from dnsfilter_list_organizations).

[DNSFilter] Remove a person's access to an organization. Destructive: a real administrator loses access to this organization immediately, and if it was their only one they lose the dashboard entirely. Their DNSFilter user account itself is NOT deleted, so the removal can be undone by re-adding them, but their permission set is not preserved. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe organization-user ID to remove (from dnsfilter_list_organization_users).
organizationIdintegeryesThe organization ID (from dnsfilter_list_organizations).

[DNSFilter] Get one user's details within a collection. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
collectionIdintegeryesThe collection ID.
idintegeryesThe user ID (from dnsfilter_list_collection_users).

[DNSFilter] Get one organization by ID (from dnsfilter_list_organizations), optionally with its current MRR. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe organization ID (from dnsfilter_list_organizations).
includeCurrentMrrbooleannonullOptional. Include current monthly recurring revenue for the organization.

[DNSFilter] Read organization-level settings — the account-wide toggles (agent auto-update, uninstall notifications, VPN settings) that dnsfilter_bulk_update_organizations writes. Scope it to one organization, several, or a whole MSP. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
mspIdintegernonullOptional. Scope to this MSP ID.
namestringnonullOptional. Filter by organization name.
organizationIdintegernonullOptional. Scope to a single organization ID.
organizationIdsstringnonullOptional. Comma-separated organization IDs to scope to. DNSFilter declares this one as a plain comma-separated string, not a repeated parameter.

[DNSFilter] Get one organization user with their role and permission set. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe user ID (from dnsfilter_list_organization_users).
includeAuthProvidersbooleannonullOptional. Include each user's authentication providers in the response. Defaults to false.
organizationIdintegeryesThe organization ID (from dnsfilter_list_organizations).

[DNSFilter] Get one DNSFilter console user by ID. Pass the literal string "self" to read the account this connection authenticates as — the id accepts either a numeric ID or "self", which is why it is a string here. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idstringyesThe user ID (from dnsfilter_list_users), or the literal "self" for the account this connection authenticates as.

[DNSFilter] List ALL organizations the account can see, DNSFilter's wider counterpart to dnsfilter_list_organizations. The vendor documents the two only as "extant" versus "all", so prefer this one when auditing coverage. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
basicInfobooleannonullOptional. True returns only each organization's basic fields, which is markedly cheaper on large MSP accounts. Defaults to false.
managedByMspIdintegernonullOptional. Return the sub-organizations managed by this MSP ID.
namestringnonullOptional. Filter by organization name.
ownedMspIdintegernonullOptional. Return the parent organizations whose MSP ID matches this value.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
typestringnonullOptional. Filter by organization type. Accepts: normal, msp, sub_organization.

[DNSFilter] List ALL DNSFilter console users, the wider counterpart to dnsfilter_list_users. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] List the users belonging to a collection — the grouping DNSFilter uses to scope policies and reporting to a set of people. Paginated and filterable by name. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
collectionIdintegeryesThe collection ID.
namestringnonullOptional. Filter by name; DNSFilter matches friendly_name first and falls back to user_name.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
sortstringnonullOptional. Sort order. Accepts: name.

[DNSFilter] List the DNSFilter console users who have access to an organization, with their roles. This is administrator access to the DNSFilter dashboard, not the end users whose DNS traffic is filtered. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
includeAuthProvidersbooleannonullOptional. Include each user's authentication providers in the response. Defaults to false.
organizationIdintegeryesThe organization ID (from dnsfilter_list_organizations).

[DNSFilter] List the organizations this account can see — for an MSP, the customer tenants. Start here: nearly every other DNSFilter tool is scoped by an organization ID. Paginated, and filterable by name, type or parent MSP. DNSFilter calls this the "extant" list; dnsfilter_list_all_organizations is the wider read. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
basicInfobooleannonullOptional. True returns only each organization's basic fields, which is markedly cheaper on large MSP accounts. Defaults to false.
excludeInheritPrivacyModebooleannonullOptional. Exclude organizations whose privacy mode is inherited from the parent.
managedByMspIdintegernonullOptional. Return the sub-organizations managed by this MSP ID.
namestringnonullOptional. Filter by organization name.
ownedMspIdintegernonullOptional. Return the parent organizations whose MSP ID matches this value.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
piiGridSearchstringnonullOptional. Search organizations by name or privacy mode, the filter DNSFilter's own PII grid uses.
typestringnonullOptional. Filter by organization type. Accepts: normal, msp, sub_organization.

[DNSFilter] List the DNSFilter console users visible to this account. Paginated. DNSFilter calls this the "extant" list; dnsfilter_list_all_users is the wider read. For who can access a PARTICULAR organization use dnsfilter_list_organization_users. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] Promote an organization to MSP status, letting it own sub-organizations. Destructive: it changes the account's tier and billing plan with DNSFilter, fires the vendor's Zapier hooks, and there is no documented demote operation. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullOptional JSON object body carrying zapier_params — values DNSFilter forwards to Zapier after a successful promotion, for example {"zapier_params": {"querystring__org_id": 1111}}. DNSFilter's spec declares this as a query parameter, which no query string can represent; it is sent as a JSON body, which its Rails backend reads identically.
planstringnonullOptional. Plan name. Accepts: manual, tier1, tier2, tier3, friendly_wifi.

[DNSFilter] Remove a user from a collection. Not destructive: it is the exact inverse of dnsfilter_add_collection_user and restores the prior state, and the user account is untouched. It does take effect on live filtering — policies scoped to this collection stop applying to them. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
collectionIdintegeryesThe collection ID.
idintegeryesThe user ID to remove (from dnsfilter_list_collection_users).

[DNSFilter] Resend the DNSFilter invitation email for a user in an organization. Marked destructive because its ONLY effect is reaching a real person's inbox — nothing in DNSFilter changes, and an email cannot be recalled, so repeated calls simply spam them. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe user ID to re-invite (from dnsfilter_list_organization_users).
organizationIdintegeryesThe organization ID (from dnsfilter_list_organizations).

[DNSFilter] Update one organization by ID (from dnsfilter_list_organizations). Send only the fields you want changed. Not destructive: it edits one record's own fields and any value can be set back. Changing privacy_mode is the exception worth care — it governs how much end-user detail DNSFilter retains in reporting, so tightening it can drop visibility your reports depend on. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in an "organization" key: {"organization": }. Fields: name, billing_contact_name, billing_contact_phone, billing_contact_email, address, managed_by_msp_id (the parent MSP), unique_id, sku, quantity, privacy_mode (inherit | standard | identify_devices | maximum), enable_cybersight, vpn_settings_organization_attributes.
idintegeryesThe organization ID (from dnsfilter_list_organizations).

[DNSFilter] Update an organization user's details, role or permissions. Send only the fields you want changed. Not destructive: every field can be set back, and the account itself is untouched. Note that organization_permission_ids REPLACES the permission set rather than adding to it, so send the full list you intend them to end up with. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "user" key: {"user": }. Fields: email, first_name, last_name, phone, role, organization_permission_ids (array of permission IDs), is_include_only_list.
idintegeryesThe organization-user ID (from dnsfilter_list_organization_users).
organizationIdintegeryesThe organization ID (from dnsfilter_list_organizations).

Networks & Sites

ToolPlanAccessSummary
dnsfilter_bulk_create_networksProWriteCreate many networks in one call.
dnsfilter_bulk_delete_networksProDestructiveDelete MANY networks in one call.
dnsfilter_bulk_update_networksProDestructiveReassign policy, scheduled policy or block page across MANY networks at once.
dnsfilter_create_ip_addressProWriteRegister a public IP address against a network, which is what makes traffic from that address get filtered by the site's policy.
dnsfilter_create_networkProWriteCreate a network (site).
dnsfilter_create_network_secret_keyProDestructiveCreate the secret key agents use to enrol against a network.
dnsfilter_create_network_subnetProWriteAdd a subnet to a network so an internal address range gets its own policy.
dnsfilter_create_networks_csv_exportProWriteStart a CSV export of networks, filtered the same way the list reads are.
dnsfilter_delete_ip_addressProDestructiveRemove a registered IP address.
dnsfilter_delete_networkProDestructiveDelete a network (site) by ID.
dnsfilter_delete_network_secret_keyProDestructiveRevoke a network's agent enrolment secret key.
dnsfilter_delete_network_subnetProDestructiveDelete a subnet from a network.
dnsfilter_get_bulk_create_networks_statusFreeRead-onlyCheck the outcome of a dnsfilter_bulk_create_networks job.
dnsfilter_get_bulk_delete_networks_statusFreeRead-onlyCheck the outcome of a dnsfilter_bulk_delete_networks job.
dnsfilter_get_bulk_update_networks_statusFreeRead-onlyCheck the outcome of a dnsfilter_bulk_update_networks job.
dnsfilter_get_ip_addressFreeRead-onlyGet one registered IP address by ID, including the network it belongs to.
dnsfilter_get_my_ipFreeRead-onlyReturn the public IP address DNSFilter sees this request coming from.
dnsfilter_get_networkFreeRead-onlyGet one network by ID, including its assigned policies, block page and IP addresses.
dnsfilter_get_network_countsFreeRead-onlyCounts of networks grouped by status — the cheap health read to run before listing anything, and across an MSP's customers in one call.
dnsfilter_get_network_lan_ipFreeRead-onlyGet one recorded LAN IP behind a network.
dnsfilter_get_network_subnetFreeRead-onlyGet one subnet of a network, including the policy and block page assigned to its address range.
dnsfilter_get_networks_csv_exportFreeRead-onlyRead back a networks CSV export by ID (from dnsfilter_create_networks_csv_export).
dnsfilter_get_networks_geoFreeRead-onlyList the account's networks with their geographic information only — the map view of where sites are.
dnsfilter_list_all_ip_addressesFreeRead-onlyList ALL registered public IP addresses, the wider counterpart to dnsfilter_list_ip_addresses.
dnsfilter_list_all_msp_networksFreeRead-onlyList ALL networks of one organization from an MSP account, the wider counterpart to dnsfilter_list_msp_networks.
dnsfilter_list_all_network_subnetsFreeRead-onlyList every site subnet the account can see, across networks.
dnsfilter_list_all_networksFreeRead-onlyList ALL networks the account can see, DNSFilter's wider counterpart to dnsfilter_list_networks.
dnsfilter_list_ip_addressesFreeRead-onlyList the public IP addresses registered to the account's networks — the addresses DNSFilter matches inbound queries against to decide which site, and therefore which policy, a query belongs to.
dnsfilter_list_msp_networksFreeRead-onlyList the networks of one organization from an MSP account.
dnsfilter_list_network_lan_ipsFreeRead-onlyList the LAN IP addresses DNSFilter has recorded behind a network — the internal addresses it has seen making queries.
dnsfilter_list_network_subnetsFreeRead-onlyList the subnets defined on one network.
dnsfilter_list_networksFreeRead-onlyList networks (sites) — a fixed location identified by its public IP, where filtering applies to everything behind that IP rather than to an installed agent.
dnsfilter_lookup_network_by_ipFreeRead-onlyFind which network owns a public IP address.
dnsfilter_rotate_network_secret_keyProDestructiveRotate a network's agent enrolment secret key.
dnsfilter_update_ip_addressProWriteUpdate a registered IP address — its value, its dynamic hostname, or the network it belongs to.
dnsfilter_update_networkProWriteUpdate one network by ID.
dnsfilter_update_network_lan_ipProWriteRename a recorded LAN IP so reports show a machine name instead of a bare address.
dnsfilter_update_network_subnetProWriteUpdate a subnet's range, policy or block page.
dnsfilter_verify_ip_addressFreeRead-onlyCheck whether an IP address is already registered in DNSFilter before you try to add it.

[DNSFilter] Create many networks in one call. Not destructive: it only adds sites. ASYNCHRONOUS — the response is a job ID, not the created networks; poll dnsfilter_get_bulk_create_networks_status with it to find out whether the work succeeded. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body: {"networks": [ ... ]}, each entry the same shape dnsfilter_create_network takes. DNSFilter's spec declares this payload as a query parameter named "Network", which no query string can represent; it is sent as a JSON body, which its Rails backend reads identically.

[DNSFilter] Delete MANY networks in one call. Destructive and irreversible — filtering stops for everything behind every listed site. ASYNCHRONOUS — the response is a job ID; poll dnsfilter_get_bulk_delete_networks_status. Confirm the id list against dnsfilter_list_networks before calling. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: ids (comma-separated network IDs), organization_id.

[DNSFilter] Reassign policy, scheduled policy or block page across MANY networks at once. Destructive: every listed site's previous assignment is overwritten with no record of what it was, which changes live filtering for everyone behind those sites. ASYNCHRONOUS — the response is a job ID; poll dnsfilter_get_bulk_update_networks_status. Body fields: ids (comma-separated network IDs), organization_id, policy_id, scheduled_policy_id, block_page_id, is_legacy_vpn_active. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: ids (comma-separated network IDs), organization_id, policy_id, scheduled_policy_id, block_page_id, is_legacy_vpn_active.

[DNSFilter] Register a public IP address against a network, which is what makes traffic from that address get filtered by the site's policy. Not destructive: it adds an address and changes nothing existing. Verify it is unclaimed first with dnsfilter_verify_ip_address. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in an "ip_address" key: {"ip_address": }. Fields: address, organization_id, network_id, dynamic_hostname (for dynamic-IP sites updated by a DDNS client).

[DNSFilter] Create a network (site). Not destructive: it adds a site and changes nothing existing. A site with no policy_ids filters nothing, so include the policies you want applied. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "network" key: {"network": }. Fields: name, organization_id, block_page_id, policy_ids (array — the filtering policies applied to this site), external_id, is_legacy_vpn_active, physical_address, ip_addresses_attributes (array of {address, key}), local_domains (array), local_resolvers (array).

[DNSFilter] Create the secret key agents use to enrol against a network. Destructive: on a site that already has one this supersedes it, and every roaming client still holding the old key stops enrolling — an outage that only shows up as machines drifting unprotected. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe network (site) ID, from dnsfilter_list_networks.

[DNSFilter] Add a subnet to a network so an internal address range gets its own policy. Not destructive: it adds a rule and changes nothing existing, though traffic from that range starts being filtered by the new policy as soon as it exists. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "network_subnet" key: {"network_subnet": }. Fields: name, from and to (the address range), policy_id, scheduled_policy_id, block_page_id.
idintegeryesThe network (site) ID, from dnsfilter_list_networks.

[DNSFilter] Start a CSV export of networks, filtered the same way the list reads are. Not destructive: it creates an export record and changes no filtering. The response is an export record, not the file — read it back with dnsfilter_get_networks_csv_export, which returns a JSON envelope carrying the link. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullOptional JSON object body, WRAPPED in a "networks_csv_export" key. Fields: organization_ids (array), msp_id, ids (array of network IDs).
ipSearchstringnonullOptional. Search by network IP or hostname.
protectedbooleannonullOptional. Return only networks that have a policy assigned.
searchstringnonullOptional. Search by network name.
statestringnonullOptional. Filter by network status. Accepts: online, offline.
unprotectedbooleannonullOptional. Return only networks with NO policy assigned — the fastest way to find sites that are not actually being filtered.

[DNSFilter] Remove a registered IP address. Destructive: queries arriving from that address stop matching the site, so everything behind it silently loses filtering while still resolving normally — the failure mode nobody notices. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe IP address record ID to remove (from dnsfilter_list_ip_addresses).

[DNSFilter] Delete a network (site) by ID. Destructive and irreversible — filtering stops for everything behind that site's IP addresses, and its subnets and IP assignments go with it. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe network ID to delete (from dnsfilter_list_networks).

[DNSFilter] Revoke a network's agent enrolment secret key. Destructive and irreversible — no agent can enrol against this site until a new key is created, and the old value cannot be recovered. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe network (site) ID, from dnsfilter_list_networks.

[DNSFilter] Delete a subnet from a network. Destructive and irreversible — the address range reverts to the parent network's policy, which usually means it is filtered differently rather than not at all, and the range definition is gone. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe network (site) ID, from dnsfilter_list_networks.
subnetIdintegeryesThe subnet ID to delete (from dnsfilter_list_network_subnets).

[DNSFilter] Check the outcome of a dnsfilter_bulk_create_networks job. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idstringyesThe job ID returned by the matching bulk call. DNSFilter runs these asynchronously, so the bulk response only queues the work — poll here for its outcome.

[DNSFilter] Check the outcome of a dnsfilter_bulk_delete_networks job. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idstringyesThe job ID returned by the matching bulk call. DNSFilter runs these asynchronously, so the bulk response only queues the work — poll here for its outcome.

[DNSFilter] Check the outcome of a dnsfilter_bulk_update_networks job. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idstringyesThe job ID returned by the matching bulk call. DNSFilter runs these asynchronously, so the bulk response only queues the work — poll here for its outcome.

[DNSFilter] Get one registered IP address by ID, including the network it belongs to. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe IP address record ID (from dnsfilter_list_ip_addresses).

[DNSFilter] Return the public IP address DNSFilter sees this request coming from. Note that is StackJack's egress address, not the customer site's — useful for confirming what a caller looks like from outside, not for registering a site. Returns raw DNSFilter JSON.

[DNSFilter] Get one network by ID, including its assigned policies, block page and IP addresses. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
countNetworkIpsbooleannonullOptional. Include a count of the network's IP addresses. Defaults to false.
idintegeryesThe network (site) ID, from dnsfilter_list_networks.

[DNSFilter] Counts of networks grouped by status — the cheap health read to run before listing anything, and across an MSP's customers in one call. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
mspIdintegernonullOptional. An MSP ID; returns counts across all of its sub-organizations.
organizationIdsstringnonullOptional. Comma-separated organization IDs. Defaults to the authenticated user's own organization.

[DNSFilter] Get one recorded LAN IP behind a network. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe network (site) ID, from dnsfilter_list_networks.
lanIpIdintegeryesThe LAN IP ID (from dnsfilter_list_network_lan_ips).

[DNSFilter] Get one subnet of a network, including the policy and block page assigned to its address range. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe network (site) ID, from dnsfilter_list_networks.
subnetIdintegeryesThe subnet ID (from dnsfilter_list_network_subnets).

[DNSFilter] Read back a networks CSV export by ID (from dnsfilter_create_networks_csv_export). Returns the export record as JSON — DNSFilter hands back an envelope carrying a link rather than CSV bytes. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe export record ID (from dnsfilter_create_networks_csv_export).

[DNSFilter] List the account's networks with their geographic information only — the map view of where sites are. Takes no parameters. Returns raw DNSFilter JSON.

[DNSFilter] List ALL registered public IP addresses, the wider counterpart to dnsfilter_list_ip_addresses. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] List ALL networks of one organization from an MSP account, the wider counterpart to dnsfilter_list_msp_networks. organizationId is REQUIRED. Note this one does not accept basic_info. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
countNetworkIpsbooleannonullOptional. Include a count of the network's IP addresses. Defaults to false.
forceTruncateIpsbooleannonullOptional. Return network information WITHOUT the IP address list, which is much smaller on sites with many addresses. Defaults to false.
organizationIdintegeryesRequired. The organization whose networks to list.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
protectedbooleannonullOptional. Return only networks that have a policy assigned.
unprotectedbooleannonullOptional. Return only networks with NO policy assigned — the fastest way to find sites that are not actually being filtered.

[DNSFilter] List every site subnet the account can see, across networks. Subnets let one site apply different policies to different internal address ranges. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
organizationIdintegernonullOptional. Restrict to one organization.

[DNSFilter] List ALL networks the account can see, DNSFilter's wider counterpart to dnsfilter_list_networks. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
basicInfobooleannonullOptional. Return only the most basic network fields. Defaults to false.
countNetworkIpsbooleannonullOptional. Include a count of the network's IP addresses. Defaults to false.
forceTruncateIpsbooleannonullOptional. Return network information WITHOUT the IP address list, which is much smaller on sites with many addresses. Defaults to false.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
protectedbooleannonullOptional. Return only networks that have a policy assigned.
searchstringnonullOptional. Free-text search across network name, hostname, IP address and similar fields.
unprotectedbooleannonullOptional. Return only networks with NO policy assigned — the fastest way to find sites that are not actually being filtered.

[DNSFilter] List the public IP addresses registered to the account's networks — the addresses DNSFilter matches inbound queries against to decide which site, and therefore which policy, a query belongs to. Paginated and searchable. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
searchstringnonullOptional. Search IP information.

[DNSFilter] List the networks of one organization from an MSP account. organizationId is REQUIRED here, unlike dnsfilter_list_networks. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
basicInfobooleannonullOptional. Return only the most basic network fields. Defaults to false.
countNetworkIpsbooleannonullOptional. Include a count of the network's IP addresses. Defaults to false.
forceTruncateIpsbooleannonullOptional. Return network information WITHOUT the IP address list, which is much smaller on sites with many addresses. Defaults to false.
organizationIdintegeryesRequired. The organization whose networks to list.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
protectedbooleannonullOptional. Return only networks that have a policy assigned.
unprotectedbooleannonullOptional. Return only networks with NO policy assigned — the fastest way to find sites that are not actually being filtered.

[DNSFilter] List the LAN IP addresses DNSFilter has recorded behind a network — the internal addresses it has seen making queries. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe network (site) ID, from dnsfilter_list_networks.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] List the subnets defined on one network. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe network (site) ID, from dnsfilter_list_networks.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] List networks (sites) — a fixed location identified by its public IP, where filtering applies to everything behind that IP rather than to an installed agent. Paginated, searchable, and filterable to protected or unprotected sites. Pass unprotected=true to find sites with no policy assigned, which are not being filtered at all. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
basicInfobooleannonullOptional. Return only the most basic network fields. Defaults to false.
countNetworkIpsbooleannonullOptional. Include a count of the network's IP addresses. Defaults to false.
forceTruncateIpsbooleannonullOptional. Return network information WITHOUT the IP address list, which is much smaller on sites with many addresses. Defaults to false.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
protectedbooleannonullOptional. Return only networks that have a policy assigned.
searchstringnonullOptional. Free-text search across network name, hostname, IP address and similar fields.
unprotectedbooleannonullOptional. Return only networks with NO policy assigned — the fastest way to find sites that are not actually being filtered.

[DNSFilter] Find which network owns a public IP address. Use this to turn an IP seen in a query log or an alert into the site it belongs to. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
requestingIpAddressstringyesRequired. The public IP address to look up.

[DNSFilter] Rotate a network's agent enrolment secret key. Destructive: the previous key stops working immediately and anything still using it — deployment scripts, imaging templates, un-enrolled agents — must be updated with the new value. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe network (site) ID, from dnsfilter_list_networks.

[DNSFilter] Update a registered IP address — its value, its dynamic hostname, or the network it belongs to. Not destructive: every field can be set back. Be aware that moving it to a different network changes which policy filters that traffic. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in an "ip_address" key: {"ip_address": }. Fields: address, organization_id, network_id, dynamic_hostname (for dynamic-IP sites updated by a DDNS client).
idintegeryesThe IP address record ID (from dnsfilter_list_ip_addresses).

[DNSFilter] Update one network by ID. Send only the fields you want changed. Not destructive — every field can be set back — but policy_ids REPLACES the assigned policy set rather than adding to it, so sending a partial list silently unassigns the policies you left out and changes what is filtered at that site. Read the current value with dnsfilter_get_network first. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "network" key: {"network": }. Fields: name, organization_id, block_page_id, policy_ids (array — the filtering policies applied to this site), external_id, is_legacy_vpn_active, physical_address, ip_addresses_attributes (array of {address, key}), local_domains (array), local_resolvers (array).
idintegeryesThe network (site) ID, from dnsfilter_list_networks.

[DNSFilter] Rename a recorded LAN IP so reports show a machine name instead of a bare address. Not destructive: name is the only editable field and it can be set back. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "network_lan_ip" key: {"network_lan_ip": {"name": "..."}}. name is the only editable field.
idintegeryesThe network (site) ID, from dnsfilter_list_networks.
lanIpIdintegeryesThe LAN IP ID (from dnsfilter_list_network_lan_ips).

[DNSFilter] Update a subnet's range, policy or block page. Send only the fields you want changed. Not destructive — every field can be set back — but the change is live for the addresses in that range. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "network_subnet" key: {"network_subnet": }. Fields: name, from and to (the address range), policy_id, scheduled_policy_id, block_page_id.
idintegeryesThe network (site) ID, from dnsfilter_list_networks.
subnetIdintegeryesThe subnet ID to update (from dnsfilter_list_network_subnets).

[DNSFilter] Check whether an IP address is already registered in DNSFilter before you try to add it. Read-only — it verifies and changes nothing. Call this first when adding a site, because an address claimed by another organization cannot be registered twice. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in an "ip_address" key: {"ip_address": }. Fields: address, organization_id, network_id, dynamic_hostname (for dynamic-IP sites updated by a DDNS client).

Roaming Clients (Agents)

ToolPlanAccessSummary
dnsfilter_check_user_agent_bulk_update_mixedFreeRead-onlyReport which attributes differ across the selected roaming clients.
dnsfilter_create_user_agent_bulk_deleteProDestructiveDelete or uninstall MANY roaming clients at once.
dnsfilter_create_user_agent_bulk_updateProDestructiveApply one changeset to MANY roaming clients.
dnsfilter_create_user_agent_cleanupProDestructiveCreate a cleanup that removes roaming clients inactive for longer than a given number of days.
dnsfilter_create_user_agent_csv_exportProWriteStart a CSV export of roaming clients, filtered the same way the list reads are.
dnsfilter_delete_user_agentProDestructiveRemove a roaming client.
dnsfilter_dequeue_uninstall_user_agentProDestructiveTake a roaming client OFF the uninstall queue.
dnsfilter_export_user_agents_csvFreeRead-onlyExport an organization's roaming clients.
dnsfilter_get_user_agentFreeRead-onlyGet one roaming client by UUID, with its hostname, platform, version, assigned policy, tags and current state.
dnsfilter_get_user_agent_bulk_deleteFreeRead-onlyRead back a bulk delete job by ID to see how it went.
dnsfilter_get_user_agent_bulk_delete_countsFreeRead-onlyCount the roaming clients a given filter set would delete.
dnsfilter_get_user_agent_bulk_updateFreeRead-onlyRead back a bulk update job by ID to see how it went.
dnsfilter_get_user_agent_bulk_update_countsFreeRead-onlyCount the roaming clients a given filter set would select.
dnsfilter_get_user_agent_cleanupFreeRead-onlyRead a stale-agent cleanup by ID, including its threshold and progress.
dnsfilter_get_user_agent_countsFreeRead-onlyCounts of roaming clients per status — the cheap fleet-health read.
dnsfilter_get_user_agent_csv_exportFreeRead-onlyRead back a roaming-client CSV export by ID (from dnsfilter_create_user_agent_csv_export).
dnsfilter_get_user_agent_uninstall_pinProRead-onlyGet the PIN that authorizes uninstalling the DNSFilter agent on an organization's machines.
dnsfilter_list_all_user_agentsFreeRead-onlyList ALL roaming clients, DNSFilter's wider counterpart to dnsfilter_list_user_agents with a narrower filter set — it takes a single organizationId rather than a list, and none of the operator…
dnsfilter_list_relay_releasesFreeRead-onlyList the latest DNSFilter relay releases per architecture, release channel and white label.
dnsfilter_list_user_agent_releasesFreeRead-onlyList the latest agent release per platform, architecture, release channel and white label.
dnsfilter_list_user_agent_tagsFreeRead-onlyList the tags in use across roaming clients.
dnsfilter_list_user_agentsFreeRead-onlyList roaming clients (agents) — the DNSFilter software installed on individual machines, which filters them wherever they are rather than only behind a site IP.
dnsfilter_update_user_agentProWriteUpdate one roaming client — friendly name, tags, assigned network, policy, scheduled policy, block page, VPN settings, or status.
dnsfilter_update_user_agent_cleanupProDestructiveUpdate a stale-agent cleanup, and START it by sending start=true.
dnsfilter_update_user_agent_settingsProWriteUpdate a roaming client's device and filtering-client settings — CyberSight, the filtering client itself, diagnostics level, and the connection, filtering and failover methods.

[DNSFilter] Report which attributes differ across the selected roaming clients. Read-only despite being a POST — it inspects and changes nothing. Use it before a bulk update to see which fields you would be flattening to a single value. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentStatestringnonullOptional. Filter by protection state. Accepts: protected, unprotected, bypassed, pending_uninstall, uninstalled, offline.
fieldsJsonstringyesJSON object body. Field: ids (array of agent UUIDs to inspect).
nameSearchstringnonullOptional. Search the client name fields — hostname and friendly name.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs. Defaults to the authenticated user's own organization.
searchstringnonullOptional. Space-delimited keyword search across status, hostname, friendly name and the currently logged-in user.
statestringnonullOptional. Filter by connectivity. Accepts: online, offline.
statusstringnonullOptional. Filter by lifecycle status. Accepts: active, disabled, uninstalled, uninstall_queued, uninstalling.
tagsstringnonullOptional. Comma-separated tags to filter by.
trafficReceivedLast15MinsbooleannonullOptional. Only agents that have received traffic in the last 15 minutes.
typestringnonullOptional. Client type. Accepts: proxy, agents. Defaults to ordinary agents, excluding proxies and relays.

[DNSFilter] Delete or uninstall MANY roaming clients at once. Destructive and the highest blast radius in the connector: with queueUninstall=true every selected machine is queued to remove its own agent and stops being filtered, and the target set is whatever the filters match rather than a list you wrote out. Always run dnsfilter_get_user_agent_bulk_delete_counts with the identical filters first. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentStatestringnonullOptional. Filter by protection state. Accepts: protected, unprotected, bypassed, pending_uninstall, uninstalled, offline.
agentVersionstringnonullOptional. Filter by agent version.
blockPageIdintegernonullOptional. Filter by block page ID.
fieldsJsonstringyesJSON object body. Fields: ids (array of agent UUIDs to include), exclude_ids (array to exclude).
nameSearchstringnonullOptional. Search the client name fields — hostname and friendly name.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all networks.
organizationIdintegernonullOptional. A single organization ID.
organizationIdsstringnonullOptional. Comma-separated organization IDs. Defaults to the authenticated user's own organization.
policyIdintegernonullOptional. Filter by policy ID.
policySchedulestringnonullOptional. Filter by policy or schedule name.
queueUninstallbooleannonullOptional. True uninstalls the agent from each selected machine; false only soft-deletes the DNSFilter records.
releaseChannelsstringnonullOptional. Filter by release channel. Values: stable, beta, preview.
releaseChannelsOperatorstringnonullOptional. How to compare release_channels. Accepts: is, isnot. Ignored unless releaseChannels is set; without it DNSFilter applies its own default comparison.
scheduledPolicyIdintegernonullOptional. Filter by scheduled policy ID.
searchstringnonullOptional. Space-delimited keyword search across status, hostname, friendly name and the currently logged-in user.
statestringnonullOptional. Filter by connectivity. Accepts: online, offline.
statusstringnonullOptional. Filter by lifecycle status. Accepts: active, disabled, uninstalled, uninstall_queued, uninstalling.
tagsstringnonullOptional. Comma-separated tags to filter by.
trafficReceivedLast15MinsbooleannonullOptional. Only agents that have received traffic in the last 15 minutes.
typestringnonullOptional. Client type. Accepts: proxy, agents. Defaults to ordinary agents, excluding proxies and relays.

[DNSFilter] Apply one changeset to MANY roaming clients. The target set is whatever the query filters select, narrowed by ids or exclude_ids in the body. Destructive: it overwrites policy, network, block page, tags or release channel across a set the caller may not have enumerated, with no record of the previous per-agent values, and it changes live filtering on real machines. Preview the target with dnsfilter_get_user_agent_bulk_update_counts and check for mixed values with dnsfilter_check_user_agent_bulk_update_mixed first. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentStatestringnonullOptional. Filter by protection state. Accepts: protected, unprotected, bypassed, pending_uninstall, uninstalled, offline.
agentVersionstringnonullOptional. Filter by agent version.
blockPageIdintegernonullOptional. Filter by block page ID.
fieldsJsonstringyesJSON object body. Fields: ids (array of agent UUIDs to include), exclude_ids (array to exclude), and changeset {network_id, policy_id, scheduled_policy_id, block_page_id, friendly_name, tags, release_channels, device_setting_attributes, filtering_client_setting_attributes, vpn_settings_user_agent}.
nameSearchstringnonullOptional. Search the client name fields — hostname and friendly name.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all networks.
organizationIdintegernonullOptional. A single organization ID.
organizationIdsstringnonullOptional. Comma-separated organization IDs. Defaults to the authenticated user's own organization.
policyIdintegernonullOptional. Filter by policy ID.
policySchedulestringnonullOptional. Filter by policy or schedule name.
releaseChannelsstringnonullOptional. Filter by release channel. Values: stable, beta, preview.
releaseChannelsOperatorstringnonullOptional. How to compare release_channels. Accepts: is, isnot. Ignored unless releaseChannels is set; without it DNSFilter applies its own default comparison.
scheduledPolicyIdintegernonullOptional. Filter by scheduled policy ID.
searchstringnonullOptional. Space-delimited keyword search across status, hostname, friendly name and the currently logged-in user.
statestringnonullOptional. Filter by connectivity. Accepts: online, offline.
statusstringnonullOptional. Filter by lifecycle status. Accepts: active, disabled, uninstalled, uninstall_queued, uninstalling.
tagsstringnonullOptional. Comma-separated tags to filter by.
trafficReceivedLast15MinsbooleannonullOptional. Only agents that have received traffic in the last 15 minutes.
typestringnonullOptional. Client type. Accepts: proxy, agents. Defaults to ordinary agents, excluding proxies and relays.

[DNSFilter] Create a cleanup that removes roaming clients inactive for longer than a given number of days. Destructive: it defines a mass deletion whose target set is a time threshold rather than a list, so a small inactiveFor value can sweep machines that are merely powered off rather than genuinely retired. Creating it does not start it — dnsfilter_update_user_agent_cleanup with start=true does. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: organization_id, organization_ids (array), inactive_for (days of inactivity that qualifies a client for removal).

[DNSFilter] Start a CSV export of roaming clients, filtered the same way the list reads are. Not destructive: it creates an export record and changes no filtering. Read the result back with dnsfilter_get_user_agent_csv_export, which returns a JSON envelope carrying the link rather than CSV bytes. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: user_agent_csv_export {organization_ids (array), msp_id, ids (array of agent UUIDs)}, plus the filter fields network_ids, type, search, name_search, tags, status, state, agent_state and traffic_received_last_15_mins.

[DNSFilter] Remove a roaming client. Destructive: by default this soft-deletes the record, and with queueUninstall=true it queues the agent to uninstall itself from the machine, which ends DNS protection there and needs a re-deployment to restore. clearRegistry additionally wipes the agent's registry keys during uninstall. To cancel an uninstall you have already queued, use dnsfilter_dequeue_uninstall_user_agent. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
clearRegistrybooleannonullOptional. Also clear the agent's registry entries while uninstalling.
idstringyesThe roaming client UUID (from dnsfilter_list_user_agents). Note this is a UUID, not a number.
queueUninstallbooleannonullOptional. Queue the agent to uninstall itself from the machine rather than only soft-deleting the DNSFilter record.

[DNSFilter] Take a roaming client OFF the uninstall queue. DNSFilter's own summary for this operation is "Remove queue", and the operation that PUTS an agent on that queue is dnsfilter_delete_user_agent with queueUninstall=true — so this cancels a pending uninstall rather than performing one. Marked destructive because it changes a pending fleet action on a real machine and the two readings of its name have opposite consequences. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idstringyesRequired. The roaming client UUID to dequeue.

[DNSFilter] Export an organization's roaming clients. Read-only — it changes nothing. Despite the name, DNSFilter declares this response as JSON, so what comes back is the export payload as raw JSON rather than CSV bytes. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
includeSuborgsbooleannonullOptional. Include sub-organizations when the organization is an MSP owner. Defaults to false.
organizationIdintegeryesRequired. The organization to export.
timezonestringnonullOptional. IANA timezone (for example America/New_York) used to localize the filename. Defaults to UTC.

[DNSFilter] Get one roaming client by UUID, with its hostname, platform, version, assigned policy, tags and current state. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idstringyesThe roaming client UUID (from dnsfilter_list_user_agents). Note this is a UUID, not a number.

[DNSFilter] Read back a bulk delete job by ID to see how it went. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe bulk delete job ID (from dnsfilter_create_user_agent_bulk_delete).

[DNSFilter] Count the roaming clients a given filter set would delete. Run this with the exact filters you intend to pass to dnsfilter_create_user_agent_bulk_delete — it is the only preview of how many machines would lose their agent. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentStatestringnonullOptional. Filter by protection state. Accepts: protected, unprotected, bypassed, pending_uninstall, uninstalled, offline.
nameSearchstringnonullOptional. Search the client name fields — hostname and friendly name.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all networks.
organizationIdintegernonullOptional. A single organization ID.
searchstringnonullOptional. Space-delimited keyword search across status, hostname, friendly name and the currently logged-in user.
statestringnonullOptional. Filter by connectivity. Accepts: online, offline.
statusstringnonullOptional. Filter by lifecycle status. Accepts: active, disabled, uninstalled, uninstall_queued, uninstalling.
tagsstringnonullOptional. Comma-separated tags to filter by.
trafficReceivedLast15MinsbooleannonullOptional. Only agents that have received traffic in the last 15 minutes.
typestringnonullOptional. Client type. Accepts: proxy, agents. Defaults to ordinary agents, excluding proxies and relays.

[DNSFilter] Read back a bulk update job by ID to see how it went. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe bulk update job ID (from dnsfilter_create_user_agent_bulk_update).

[DNSFilter] Count the roaming clients a given filter set would select. Run this with the exact filters you intend to pass to dnsfilter_create_user_agent_bulk_update — it is the only way to see the blast radius before committing to it. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentStatestringnonullOptional. Filter by protection state. Accepts: protected, unprotected, bypassed, pending_uninstall, uninstalled, offline.
blockPageIdintegernonullOptional. Filter by block page ID.
nameSearchstringnonullOptional. Search the client name fields — hostname and friendly name.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all networks.
organizationIdintegernonullOptional. A single organization ID.
policyIdintegernonullOptional. Filter by policy ID.
releaseChannelsstringnonullOptional. Filter by release channel. Values: stable, beta, preview.
releaseChannelsOperatorstringnonullOptional. How to compare release_channels. Accepts: is, isnot. Ignored unless releaseChannels is set; without it DNSFilter applies its own default comparison.
scheduledPolicyIdintegernonullOptional. Filter by scheduled policy ID.
searchstringnonullOptional. Space-delimited keyword search across status, hostname, friendly name and the currently logged-in user.
statestringnonullOptional. Filter by connectivity. Accepts: online, offline.
statusstringnonullOptional. Filter by lifecycle status. Accepts: active, disabled, uninstalled, uninstall_queued, uninstalling.
tagsstringnonullOptional. Comma-separated tags to filter by.
trafficReceivedLast15MinsbooleannonullOptional. Only agents that have received traffic in the last 15 minutes.
typestringnonullOptional. Client type. Accepts: proxy, agents. Defaults to ordinary agents, excluding proxies and relays.

[DNSFilter] Read a stale-agent cleanup by ID, including its threshold and progress. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe cleanup ID (from dnsfilter_create_user_agent_cleanup).

[DNSFilter] Counts of roaming clients per status — the cheap fleet-health read. Answers "how many machines are unprotected right now" without paging the whole inventory. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
mspIdintegernonullOptional. An MSP ID; widens the scope to all of its sub-organizations.
nameSearchstringnonullOptional. Search the client name fields — hostname and friendly name.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all networks.
newAgentStatesbooleannonullOptional. Use DNSFilter's newer agent-state vocabulary (Protected, Unprotected, Offline) instead of the legacy one.
organizationIdsstringnonullOptional. Comma-separated organization IDs. Defaults to the authenticated user's own organization.
releaseChannelsstringnonullOptional. Filter by release channel. Values: stable, beta, preview.
releaseChannelsOperatorstringnonullOptional. How to compare release_channels. Accepts: is, isnot. Ignored unless releaseChannels is set; without it DNSFilter applies its own default comparison.
searchstringnonullOptional. Space-delimited keyword search across status, hostname, friendly name and the currently logged-in user.
statestringnonullOptional. Filter by connectivity. Accepts: online, offline.
statusstringnonullOptional. Filter by status. Accepts: active, disabled, uninstalled.
tagsstringnonullOptional. Comma-separated tags to filter by.
typestringnonullOptional. Client type. Accepts: proxy, agents. Defaults to ordinary agents, excluding proxies and relays.

[DNSFilter] Read back a roaming-client CSV export by ID (from dnsfilter_create_user_agent_csv_export). Returns the export record as JSON. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe export record ID (from dnsfilter_create_user_agent_csv_export).

[DNSFilter] Get the PIN that authorizes uninstalling the DNSFilter agent on an organization's machines. Read-only, but the value IS a secret — it is what stops an end user removing their own protection, and it works for the organization's whole fleet — which is why this sits behind its own permission (read:uninstall-pins) and the Pro tier rather than the general agent-read permission. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
organizationIdintegeryesRequired. The organization whose PIN to read.

[DNSFilter] List ALL roaming clients, DNSFilter's wider counterpart to dnsfilter_list_user_agents with a narrower filter set — it takes a single organizationId rather than a list, and none of the operator filters. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentLocalUserUuidsstringnonullOptional. Comma-separated local-user UUIDs to scope to.
cybersightEnabledbooleannonullOptional. Answer from CyberSight activity over the start/end window instead of DNSFilter's own database. Defaults to false.
endAtstringnonullOptional. ISO8601 end of the activity window.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all networks.
organizationIdintegernonullOptional. A SINGLE organization ID to scope to.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
searchstringnonullOptional. Space-delimited keyword search across status, hostname, friendly name and the currently logged-in user.
sortstringnonullOptional. Sort by hostname, friendly_name, agent_version or last_sync.
startAtstringnonullOptional. ISO8601 start of the activity window.
statestringnonullOptional. Filter by connectivity. Accepts: online, offline.
statusstringnonullOptional. Filter by lifecycle status. Accepts: active, disabled, uninstalled, uninstall_queued, uninstalling.
tagsstringnonullOptional. Comma-separated tags to filter by.
typestringnonullOptional. Client type. Accepts: proxy, agents. Defaults to ordinary agents, excluding proxies and relays.

[DNSFilter] List the latest DNSFilter relay releases per architecture, release channel and white label. Relays are the on-premises forwarders, distinct from the roaming client. Takes no parameters. Returns raw DNSFilter JSON.

[DNSFilter] List the latest agent release per platform, architecture, release channel and white label. Compare against the versions in dnsfilter_list_user_agents to find machines running something older than what is shipping. Takes no parameters. Returns raw DNSFilter JSON.

[DNSFilter] List the tags in use across roaming clients. Tags are how bulk operations select machines, so read this before targeting a bulk update or delete by tag. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
includeUsedOnlybooleannonullOptional. Drop tags that are not currently applied to any client.
mspIdintegernonullOptional. An MSP ID; widens the scope to all of its sub-organizations.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all networks.
organizationIdsstringnonullOptional. Comma-separated organization IDs. Defaults to the authenticated user's own organization.

[DNSFilter] List roaming clients (agents) — the DNSFilter software installed on individual machines, which filters them wherever they are rather than only behind a site IP. This is the main fleet inventory read and the widest filter surface in the connector: protection state, connectivity, version, VPN status, browser-extension status, CyberSight status, tags, policy and more. To find unprotected machines, filter agentState=unprotected. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
agentLocalUserUuidsstringnonullOptional. Comma-separated local-user UUIDs; returns the roaming clients associated with those users.
agentStatestringnonullOptional. Filter by protection state. Accepts: protected, unprotected, bypassed, pending_uninstall, uninstalled, offline.
agentTypestringnonullOptional. Filter by platform. Values: windows, macos, ios, android, chrome.
agentTypeOperatorstringnonullOptional. How to compare agent_type. Accepts: is, isnot. Ignored unless agentType is set; without it DNSFilter applies its own default comparison.
agentVersionstringnonullOptional. Filter by installed agent version.
agentVersionOperatorstringnonullOptional. How to compare agent_version. Accepts: startswith, equals, doesnotequal, contains, doesnotcontain, endswith. Ignored unless agentVersion is set; without it DNSFilter applies its own default comparison.
autoUpdatebooleannonullOptional. Filter by the organization's agent auto-update setting.
blockPageIdintegernonullOptional. Filter by assigned block page ID.
browserExtensionStatusstringnonullOptional. Filter by Chrome/Edge extension state. Values: installed, not_responding, not_installed.
browserExtensionStatusOperatorstringnonullOptional. How to compare browser_extension_status. Accepts: is, isnot. Ignored unless browserExtensionStatus is set; without it DNSFilter applies its own default comparison.
cybersightEnabledbooleannonullOptional. When true DNSFilter answers from CyberSight activity over the start/end window instead of its own database, which changes what the other filters mean. Defaults to false.
cybersightStatusstringnonullOptional. Filter by CyberSight service status. Values: active, inactive, disabled, not_available.
cybersightStatusOperatorstringnonullOptional. How to compare cybersight_status. Accepts: is, isnot. Ignored unless cybersightStatus is set; without it DNSFilter applies its own default comparison.
endAtstringnonullOptional. ISO8601 end of the activity window. Only used with startAt when cybersightEnabled is true.
mspIdintegernonullOptional. An MSP ID; widens the scope to all of its sub-organizations.
nameSearchstringnonullOptional. Search hostname and friendly name.
nameSearchOperatorstringnonullOptional. How to compare name_search. Accepts: contains, doesnotcontain. Ignored unless nameSearch is set; without it DNSFilter applies its own default comparison.
networkIdsstringnonullOptional. Comma-separated network IDs. Defaults to all networks.
newAgentStatesbooleannonullOptional. Use DNSFilter's newer agent-state vocabulary (Protected, Unprotected, Offline) instead of the legacy one.
organizationIdsstringnonullOptional. Comma-separated organization IDs. Defaults to the authenticated user's own organization.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
policyIdintegernonullOptional. Filter by assigned policy ID.
policySchedulestringnonullOptional. Filter by policy or schedule name.
releaseChannelsstringnonullOptional. Filter by release channel. Values: stable, beta, preview.
releaseChannelsOperatorstringnonullOptional. How to compare release_channels. Accepts: is, isnot. Ignored unless releaseChannels is set; without it DNSFilter applies its own default comparison.
scheduledPolicyIdintegernonullOptional. Filter by assigned scheduled policy ID.
searchstringnonullOptional. Space-delimited keyword search across status, hostname, friendly name and the currently logged-in user.
sortstringnonullOptional. Sort by hostname, friendly_name, agent_version, last_sync, agent_state, vpn_status or private_network.
startAtstringnonullOptional. ISO8601 start of the activity window. Only used when cybersightEnabled is true; omitted it means the last 91 days.
statestringnonullOptional. Filter by connectivity. Accepts: online, offline.
statusstringnonullOptional. Filter by lifecycle status. Accepts: active, disabled, uninstalled, uninstall_queued, uninstalling.
tagsstringnonullOptional. Comma-separated tags to filter by.
trafficReceivedLast15MinsbooleannonullOptional. Only agents that have received traffic in the last 15 minutes.
typestringnonullOptional. Client type. Accepts: proxy, agents. Defaults to ordinary agents, excluding proxies and relays.
vpnModestringnonullOptional. Filter by VPN mode; an agent-level setting overrides the organization one. Values: manual, always_on.
vpnModeOperatorstringnonullOptional. How to compare vpn_mode. Accepts: is, isnot. Ignored unless vpnMode is set; without it DNSFilter applies its own default comparison.
vpnStatusstringnonullOptional. Filter by VPN connectivity. Values: connected, not_connected, disabled.
vpnStatusOperatorstringnonullOptional. How to compare vpn_status. Accepts: is, isnot. Ignored unless vpnStatus is set; without it DNSFilter applies its own default comparison.

[DNSFilter] Update one roaming client — friendly name, tags, assigned network, policy, scheduled policy, block page, VPN settings, or status. Send only the fields you want changed. Not destructive as a field edit, and any value can be set back, but two fields carry real weight: status accepts "uninstalled", which removes protection from that machine, and tags REPLACES the tag set rather than adding to it — and tags are how bulk operations select machines. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "user_agent" key: {"user_agent": }. Fields: friendly_name, status (active | disabled | uninstalled), network_id, policy_id, scheduled_policy_id, block_page_id, tags (array — replaces the whole set), vpn_settings_user_agent_attributes.
idstringyesThe roaming client UUID (from dnsfilter_list_user_agents). Note this is a UUID, not a number.

[DNSFilter] Update a stale-agent cleanup, and START it by sending start=true. Destructive: starting one deletes every roaming client that matches the inactivity threshold, in bulk and without a further confirmation. Check the threshold with dnsfilter_get_user_agent_cleanup before starting. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: start (true begins the deletion run), inactive_for (days of inactivity that qualifies a client for removal).
idintegeryesThe cleanup ID (from dnsfilter_create_user_agent_cleanup).

[DNSFilter] Update a roaming client's device and filtering-client settings — CyberSight, the filtering client itself, diagnostics level, and the connection, filtering and failover methods. Not destructive: these are reversible settings on one machine. Note this is the connector's /v2 endpoint for agents while the ordinary update is /v1; they edit different fields and neither is a newer version of the other. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "user_agent" key. Fields: device_setting_attributes {id, enable_cyber_sight, enable_filtering_client, diagnostics_level} and filtering_client_setting_attributes {id, connection_method, filtering_method, fail_over_method}.
idstringyesThe roaming client UUID (from dnsfilter_list_user_agents). Note this is a UUID, not a number.

Policies & Filtering Lists

ToolPlanAccessSummary
dnsfilter_add_policy_allowed_applicationProWriteAllow one application in a policy.
dnsfilter_add_policy_allowed_domainProWriteAdd one domain to a policy's allow list, exempting it from category and threat blocking for everyone the policy covers.
dnsfilter_add_policy_blocked_applicationProWriteBlock one application in a policy — this stops it working for everyone the policy covers, so check what depends on it first.
dnsfilter_add_policy_blocked_categoryProWriteBlock a whole content category in a policy.
dnsfilter_add_policy_blocked_domainProWriteAdd one domain to a policy's block list.
dnsfilter_bulk_add_policy_allowed_domainsProWriteAdd several domains to several policies' allow lists in one call.
dnsfilter_bulk_add_policy_blocked_domainsProWriteAdd several domains to several policies' block lists in one call — the fastest way to push an indicator of compromise across every customer.
dnsfilter_bulk_remove_policy_allowed_domainsProWriteRemove several domains from several policies' allow lists.
dnsfilter_bulk_remove_policy_blocked_domainsProWriteRemove several domains from several policies' block lists, so they resolve again wherever those policies apply.
dnsfilter_create_policyProWriteCreate a filtering policy.
dnsfilter_delete_policyProDestructiveDelete a policy.
dnsfilter_get_application_policiesFreeRead-onlyShow how each policy currently treats one application — which policies allow it and which block it.
dnsfilter_get_policyFreeRead-onlyGet one policy by ID with its full rule set — allowed and blocked domains, blocked categories, application rules and the safe-search and YouTube-restriction flags.
dnsfilter_get_policy_ipFreeRead-onlyGet one policy IP by ID.
dnsfilter_get_policy_permissive_modeFreeRead-onlyRead whether a policy is in permissive mode.
dnsfilter_list_all_policiesFreeRead-onlyList ALL policies the account can see, the wider counterpart to dnsfilter_list_policies.
dnsfilter_list_policiesFreeRead-onlyList filtering policies — the rule sets that decide which domains, categories and applications are allowed or blocked.
dnsfilter_list_policy_ipsFreeRead-onlyList the policy IPs — the DNSFilter resolver addresses a policy answers on, which is what a site or device points its DNS at.
dnsfilter_remove_policy_allowed_applicationProWriteRemove one application from a policy's allow list.
dnsfilter_remove_policy_allowed_domainProWriteRemove one domain from a policy's allow list, so the ordinary category and threat rules apply to it again.
dnsfilter_remove_policy_blocked_applicationProWriteRemove one application from a policy's block list, letting it work again.
dnsfilter_remove_policy_blocked_categoryProWriteStop blocking a content category in a policy.
dnsfilter_remove_policy_blocked_domainProWriteRemove one domain from a policy's block list, so it resolves normally again unless another rule still blocks it.
dnsfilter_set_policy_permissive_modeProDestructiveTurn a policy's permissive mode on or off.
dnsfilter_update_application_policiesProDestructiveSet which policies allow and which block one application, in a single call.
dnsfilter_update_policyProWriteUpdate a policy.

[DNSFilter] Allow one application in a policy. Not destructive: a single reversible list-membership change with an exact inverse. Application names come from dnsfilter_list_applications. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: name (the application name, from dnsfilter_list_applications), include_relationships.
idintegeryesThe policy ID (from dnsfilter_list_policies).

[DNSFilter] Add one domain to a policy's allow list, exempting it from category and threat blocking for everyone the policy covers. Not destructive: a single reversible list-membership change with an exact inverse. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: domain (the single domain to act on), note (free text recorded against it), include_relationships.
idintegeryesThe policy ID (from dnsfilter_list_policies).

[DNSFilter] Block one application in a policy — this stops it working for everyone the policy covers, so check what depends on it first. Not destructive: a single reversible list-membership change with an exact inverse. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: name (the application name, from dnsfilter_list_applications), include_relationships.
idintegeryesThe policy ID (from dnsfilter_list_policies).

[DNSFilter] Block a whole content category in a policy. Wider in effect than a single domain — a category covers many sites — but still a single reversible list-membership change with an exact inverse, so it is not marked destructive. Category IDs come from dnsfilter_list_categories. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: category_id (from dnsfilter_list_categories), include_relationships.
idintegeryesThe policy ID (from dnsfilter_list_policies).

[DNSFilter] Add one domain to a policy's block list. Takes effect on live filtering immediately for everyone the policy covers. Not destructive: it is a single reversible list-membership change that dnsfilter_remove_policy_blocked_domain undoes exactly, restoring the prior state. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: domain (the single domain to act on), note (free text recorded against it), include_relationships.
idintegeryesThe policy ID (from dnsfilter_list_policies).

[DNSFilter] Add several domains to several policies' allow lists in one call. Not destructive: it only adds entries, changes nothing already there, and dnsfilter_bulk_remove_policy_allowed_domains is its exact inverse. It does exempt those domains from filtering everywhere the listed policies apply. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: domains (array), policy_ids (array of the policies to change), notes (an object mapping each domain to a note).

[DNSFilter] Add several domains to several policies' block lists in one call — the fastest way to push an indicator of compromise across every customer. Not destructive: it only adds entries and has an exact inverse. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: domains (array), policy_ids (array of the policies to change), notes (an object mapping each domain to a note).

[DNSFilter] Remove several domains from several policies' allow lists. Not destructive: it removes only the entries you name, leaving the rest of each list intact, and re-adding them restores the prior state exactly. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: domains (array), policy_ids (array of the policies to change), notes (an object mapping each domain to a note).

[DNSFilter] Remove several domains from several policies' block lists, so they resolve again wherever those policies apply. Not destructive: it removes only the entries you name and re-adding them restores the prior state exactly. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: domains (array), policy_ids (array of the policies to change), notes (an object mapping each domain to a note).

[DNSFilter] Create a filtering policy. Not destructive: it adds a rule set and nothing is filtered by it until a network, subnet or roaming client is assigned to it. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "policy" key: {"policy": }. Fields: name, organization_id, allow_unknown_domains, google_safesearch, bing_safe_search, duck_duck_go_safe_search, ecosia_safesearch, yandex_safe_search, youtube_restricted, youtube_restricted_level (strict | none), interstitial, policy_ip_id, whitelist_domains (array), blacklist_domains (array), blacklist_categories (array of category IDs), allow_applications (array), block_applications (array), is_global_policy, allow_list_only, lock_version. Two sibling flags sit OUTSIDE the "policy" key: include_relationships and append_domains.

[DNSFilter] Delete a policy. Destructive and irreversible — the whole rule set goes, and every network, subnet and roaming client assigned to it stops being filtered by those rules. Check what is assigned to it before calling. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe policy ID to delete (from dnsfilter_list_policies).

[DNSFilter] Show how each policy currently treats one application — which policies allow it and which block it. Run this before dnsfilter_update_application_policies, whose arrays replace that state wholesale. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
applicationIdintegeryesRequired. The application ID (from dnsfilter_list_applications).
namestringnonullOptional. Full or partial policy name to narrow the result.
organizationIdintegeryesRequired. The organization to query.
policyIdsstringnonullOptional. Comma-separated policy IDs to restrict the result to.

[DNSFilter] Get one policy by ID with its full rule set — allowed and blocked domains, blocked categories, application rules and the safe-search and YouTube-restriction flags. Read this before any change: the update tool replaces list fields wholesale by default. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe policy ID (from dnsfilter_list_policies).
includeRelationshipsbooleannonullOptional. Include related records in the response. DNSFilter defaults this to true, so pass false for a smaller payload.

[DNSFilter] Get one policy IP by ID. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe policy IP ID (from dnsfilter_list_policy_ips).

[DNSFilter] Read whether a policy is in permissive mode. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe policy ID (from dnsfilter_list_policies).

[DNSFilter] List ALL policies the account can see, the wider counterpart to dnsfilter_list_policies. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
includeGlobalPoliciesbooleannonullOptional. Also include global policies.
organizationIdintegernonullOptional. Restrict to one organization.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] List filtering policies — the rule sets that decide which domains, categories and applications are allowed or blocked. Policies are what networks and roaming clients get assigned, so read this before assigning anything. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
includeGlobalPoliciesbooleannonullOptional. Also include global policies, which apply across organizations.
organizationIdintegernonullOptional. Restrict to one organization.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] List the policy IPs — the DNSFilter resolver addresses a policy answers on, which is what a site or device points its DNS at. Takes no parameters. Returns raw DNSFilter JSON.

[DNSFilter] Remove one application from a policy's allow list. Not destructive: the exact inverse of dnsfilter_add_policy_allowed_application. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: name (the application name, from dnsfilter_list_applications), include_relationships.
idintegeryesThe policy ID (from dnsfilter_list_policies).

[DNSFilter] Remove one domain from a policy's allow list, so the ordinary category and threat rules apply to it again. Not destructive: the exact inverse of dnsfilter_add_policy_allowed_domain. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: domain (the single domain to act on), note (free text recorded against it), include_relationships.
idintegeryesThe policy ID (from dnsfilter_list_policies).

[DNSFilter] Remove one application from a policy's block list, letting it work again. Not destructive: the exact inverse of dnsfilter_add_policy_blocked_application. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: name (the application name, from dnsfilter_list_applications), include_relationships.
idintegeryesThe policy ID (from dnsfilter_list_policies).

[DNSFilter] Stop blocking a content category in a policy. Everything in that category resolves again unless another rule catches it, which is a real widening of what users can reach. Not destructive: the exact inverse of dnsfilter_add_policy_blocked_category. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: category_id (from dnsfilter_list_categories), include_relationships.
idintegeryesThe policy ID (from dnsfilter_list_policies).

[DNSFilter] Remove one domain from a policy's block list, so it resolves normally again unless another rule still blocks it. Not destructive: the exact inverse of dnsfilter_add_policy_blocked_domain, restoring the prior state. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: domain (the single domain to act on), note (free text recorded against it), include_relationships.
idintegeryesThe policy ID (from dnsfilter_list_policies).

[DNSFilter] Turn a policy's permissive mode on or off. Destructive: switching it ON relaxes enforcement for every network and machine assigned to this policy at once — traffic that was being blocked stops being blocked, silently and immediately. It is reversible by setting it back to false, but nothing records that it was ever changed. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe policy ID (from dnsfilter_list_policies).
permissiveModebooleanyesRequired. True enables permissive mode, false enforces the policy normally.

[DNSFilter] Set which policies allow and which block one application, in a single call. Destructive: both lists are REPLACED, not merged, so any policy you omit from both arrays loses whatever rule it had for this application — and this is live filtering for everyone those policies cover. Read the current state with dnsfilter_get_application_policies and send it back with your change applied. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
allowPoliciesstringyesRequired. Comma-separated policy IDs that should ALLOW this application. This replaces the current allow set.
applicationIdintegeryesRequired. The application ID (from dnsfilter_list_applications).
blockPoliciesstringyesRequired. Comma-separated policy IDs that should BLOCK this application. This replaces the current block set.
organizationIdintegeryesRequired. The organization to apply this to.

[DNSFilter] Update a policy. Send only the fields you want changed. Not destructive as a field edit — every value can be set back — but mind the list semantics: whitelist_domains, blacklist_domains, blacklist_categories and the application lists REPLACE the existing set unless you send append_domains=true, so a partial list silently drops the entries you left out and changes live filtering. To change one entry, prefer the add/remove tools (dnsfilter_add_policy_blocked_domain and its siblings), which cannot have that effect. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "policy" key: {"policy": }. Fields: name, organization_id, allow_unknown_domains, google_safesearch, bing_safe_search, duck_duck_go_safe_search, ecosia_safesearch, yandex_safe_search, youtube_restricted, youtube_restricted_level (strict | none), interstitial, policy_ip_id, whitelist_domains (array), blacklist_domains (array), blacklist_categories (array of category IDs), allow_applications (array), block_applications (array), is_global_policy, allow_list_only, lock_version. Two sibling flags sit OUTSIDE the "policy" key: include_relationships and append_domains.
idintegeryesThe policy ID (from dnsfilter_list_policies).

Agent Local Users

ToolPlanAccessSummary
dnsfilter_create_agent_local_user_bulk_deleteProDestructiveDelete MANY agent local users at once.
dnsfilter_create_agent_local_users_csv_exportProWriteStart a CSV export of agent local users.
dnsfilter_delete_agent_local_userProDestructiveDelete an agent local user record.
dnsfilter_get_agent_local_userFreeRead-onlyGet one agent local user by ID, with their assigned policy, scheduled policy and block page.
dnsfilter_get_agent_local_user_bulk_deleteFreeRead-onlyRead back a bulk delete job by ID to see how it went.
dnsfilter_get_agent_local_user_bulk_delete_countFreeRead-onlyCount the users covered by a bulk delete job.
dnsfilter_get_agent_local_user_countsFreeRead-onlyCounts of agent local users grouped by policy-assignment status — how many have a policy of their own versus inheriting one.
dnsfilter_get_agent_local_users_csv_exportFreeRead-onlyRead back an agent local users CSV export.
dnsfilter_list_agent_local_usersFreeRead-onlyList agent local users — the people signed in to machines running the roaming client, which is how DNSFilter attributes traffic and applies per-user policy.
dnsfilter_list_all_agent_local_usersFreeRead-onlyList ALL agent local users, the wider counterpart to dnsfilter_list_agent_local_users with a narrower filter set — none of the operator filters.
dnsfilter_update_agent_local_userProWriteUpdate an agent local user's friendly name, or assign them a policy, scheduled policy or block page directly.

[DNSFilter] Delete MANY agent local users at once. Destructive: the target set is whatever the operator filters match, narrowed by ids or exclude_ids in the body, so a broad filter can remove far more identities than intended — and every per-user policy assignment in that set goes with them. Check the size first with dnsfilter_get_agent_local_user_bulk_delete_count. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
blockPagestringnonullOptional. Filter by the assigned block page name.
blockPageOperatorstringnonullOptional. How to compare block_page. Accepts: contains, doesnotcontain. Ignored unless blockPage is set; without it DNSFilter applies its own default comparison.
collectionIdstringnonullOptional. Filter by collection.
collectionIdOperatorstringnonullOptional. How to compare collection_id. Accepts: is, isnot. Ignored unless collectionId is set; without it DNSFilter applies its own default comparison.
fieldsJsonstringyesJSON object body. Fields: ids (array of agent local user IDs to include), exclude_ids (array to exclude).
friendlyNamestringnonullOptional. Filter by friendly name.
friendlyNameOperatorstringnonullOptional. How to compare friendly_name. Accepts: contains, doesnotcontain. Ignored unless friendlyName is set; without it DNSFilter applies its own default comparison.
nameSearchstringnonullOptional. Search friendly_name, falling back to user_name when it is absent.
policySchedulestringnonullOptional. Filter by policy or scheduled policy name.
policyScheduleOperatorstringnonullOptional. How to compare policy_schedule. Accepts: contains, doesnotcontain. Ignored unless policySchedule is set; without it DNSFilter applies its own default comparison.
searchstringnonullOptional. Filter by name or user login.
userLoginstringnonullOptional. Filter by user login.
userLoginOperatorstringnonullOptional. How to compare user_login. Accepts: contains, doesnotcontain. Ignored unless userLogin is set; without it DNSFilter applies its own default comparison.
userNamestringnonullOptional. Filter by username.
userNameOperatorstringnonullOptional. How to compare user_name. Accepts: contains, doesnotcontain. Ignored unless userName is set; without it DNSFilter applies its own default comparison.

[DNSFilter] Start a CSV export of agent local users. Not destructive: it creates an export record and changes no filtering. Read the result back with dnsfilter_get_agent_local_users_csv_export, which returns a JSON envelope carrying the link rather than CSV bytes. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in an "agent_local_users_csv_export" key. Fields: organization_ids (array), name, search, user_policy_override.

[DNSFilter] Delete an agent local user record. Destructive: their per-user policy assignment and their history as a distinct identity go with it, so traffic from that person stops being attributed to them in reporting. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe agent local user ID to delete (from dnsfilter_list_agent_local_users).

[DNSFilter] Get one agent local user by ID, with their assigned policy, scheduled policy and block page. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe agent local user ID (from dnsfilter_list_agent_local_users).

[DNSFilter] Read back a bulk delete job by ID to see how it went. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe bulk delete job ID (from dnsfilter_create_agent_local_user_bulk_delete).

[DNSFilter] Count the users covered by a bulk delete job. Note this takes the JOB id as a query parameter rather than a filter set, so it reports on a job that already exists — unlike the roaming-client counts endpoints, which preview a filter before you commit to it. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesRequired. The bulk delete job ID (from dnsfilter_create_agent_local_user_bulk_delete).

[DNSFilter] Counts of agent local users grouped by policy-assignment status — how many have a policy of their own versus inheriting one. The cheap read for spotting users nobody has scoped. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
mspIdintegernonullOptional. An MSP ID; counts across all of its organizations.
namestringnonullOptional. Filter by name; DNSFilter matches friendly_name first and falls back to user_name.
organizationIdsstringnonullOptional. Comma-separated organization IDs. Defaults to the authenticated user's own organization.
searchstringnonullOptional. Filter by name or user login.

[DNSFilter] Read back an agent local users CSV export. The id is a UUID string here, not a number — unlike the other export reads in this connector. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idstringyesThe export UUID (from dnsfilter_create_agent_local_users_csv_export). A UUID string, not a number.

[DNSFilter] List agent local users — the people signed in to machines running the roaming client, which is how DNSFilter attributes traffic and applies per-user policy. These are NOT DNSFilter console accounts (see dnsfilter_list_organization_users) and NOT collection members. Paginated, with operator filters on name, login, block page, collection and policy schedule. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
blockPagestringnonullOptional. Filter by the assigned block page name.
blockPageOperatorstringnonullOptional. How to compare block_page. Accepts: contains, doesnotcontain. Ignored unless blockPage is set; without it DNSFilter applies its own default comparison.
collectionIdstringnonullOptional. Filter by collection. The value is a collection ID, or a comma-separated list of them.
collectionIdOperatorstringnonullOptional. How to compare collection_id. Accepts: is, isnot. Ignored unless collectionId is set; without it DNSFilter applies its own default comparison.
cybersightEnabledbooleannonullOptional. When true DNSFilter answers from CyberSight activity over the start/end window instead of its own database, which changes what the other filters mean. Defaults to false.
endAtstringnonullOptional. ISO8601 end of the activity window. Only used with startAt when cybersightEnabled is true.
friendlyNamestringnonullOptional. Filter by friendly name.
friendlyNameOperatorstringnonullOptional. How to compare friendly_name. Accepts: contains, doesnotcontain. Ignored unless friendlyName is set; without it DNSFilter applies its own default comparison.
idsstringnonullOptional. Comma-separated agent local user IDs to restrict the result to.
inACollectionbooleannonullOptional. True returns only users that belong to a collection.
mspIdintegernonullOptional. An MSP ID; returns local users across all of its organizations.
namestringnonullOptional. Filter by name; DNSFilter matches friendly_name first and falls back to user_name.
organizationIdsstringnonullOptional. Comma-separated organization IDs. Defaults to the authenticated user's own organization.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
policySchedulestringnonullOptional. Filter by policy or scheduled policy name.
policyScheduleOperatorstringnonullOptional. How to compare policy_schedule. Accepts: contains, doesnotcontain. Ignored unless policySchedule is set; without it DNSFilter applies its own default comparison.
searchstringnonullOptional. Filter by name or user login.
sortstringnonullOptional. Sort by name, first_seen or last_seen. Prefix with - for descending, for example -first_seen.
startAtstringnonullOptional. ISO8601 start of the activity window. Only used when cybersightEnabled is true; omitted it means the last 91 days.
userAgentUuidsstringnonullOptional. Comma-separated roaming client UUIDs; returns the local users seen on those clients.
userLoginstringnonullOptional. Filter by user login.
userLoginOperatorstringnonullOptional. How to compare user_login. Accepts: contains, doesnotcontain. Ignored unless userLogin is set; without it DNSFilter applies its own default comparison.
userNamestringnonullOptional. Filter by username.
userNameOperatorstringnonullOptional. How to compare user_name. Accepts: contains, doesnotcontain. Ignored unless userName is set; without it DNSFilter applies its own default comparison.
userPolicyOverridebooleannonullOptional. True returns only users with a policy or scheduled policy assigned directly to them; false returns only those without one. Omit for both.

[DNSFilter] List ALL agent local users, the wider counterpart to dnsfilter_list_agent_local_users with a narrower filter set — none of the operator filters. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
cybersightEnabledbooleannonullOptional. When true DNSFilter answers from CyberSight activity over the start/end window instead of its own database, which changes what the other filters mean. Defaults to false.
endAtstringnonullOptional. ISO8601 end of the activity window.
inACollectionbooleannonullOptional. True returns only users that belong to a collection.
namestringnonullOptional. Filter by name; DNSFilter matches friendly_name first and falls back to user_name.
organizationIdsstringnonullOptional. Comma-separated organization IDs. Defaults to the authenticated user's own organization.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.
sortstringnonullOptional. Sort by name.
startAtstringnonullOptional. ISO8601 start of the activity window.
userAgentUuidsstringnonullOptional. Comma-separated roaming client UUIDs; returns the local users seen on those clients.
userPolicyOverridebooleannonullOptional. True returns only users with a policy or scheduled policy assigned directly to them; false returns only those without one. Omit for both.

[DNSFilter] Update an agent local user's friendly name, or assign them a policy, scheduled policy or block page directly. Not destructive: every field can be set back. Assigning a policy here overrides whatever they would inherit from their network or collection, which is live filtering for that person. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in an "agent_local_user" key. Fields: friendly_name, policy_id, scheduled_policy_id, block_page_id.
idintegeryesThe agent local user ID (from dnsfilter_list_agent_local_users).

Categories & Applications

ToolPlanAccessSummary
dnsfilter_get_applicationFreeRead-onlyGet one application by ID.
dnsfilter_get_application_categoryFreeRead-onlyGet one application category by ID.
dnsfilter_get_categoryFreeRead-onlyGet one content category by ID.
dnsfilter_list_ai_applicationsFreeRead-onlyList the AI applications and websites DNSFilter recognises — the reference set behind AI-usage reporting and the starting point for building a policy around generative-AI access.
dnsfilter_list_all_applicationsFreeRead-onlyList ALL applications INCLUDING deleted ones, which dnsfilter_list_applications omits.
dnsfilter_list_all_categoriesFreeRead-onlyList ALL content categories INCLUDING DNSFilter's internal ones, which dnsfilter_list_categories omits.
dnsfilter_list_application_categoriesFreeRead-onlyList the application categories — the grouping over applications, and a different axis from the CONTENT categories in dnsfilter_list_categories.
dnsfilter_list_applicationsFreeRead-onlyList the applications DNSFilter can allow or block by name — the vocabulary the policy application tools expect.
dnsfilter_list_categoriesFreeRead-onlyList DNSFilter's content categories — the buckets ("Malware", "Social Media", and so on) a policy blocks by ID.
dnsfilter_list_cybersight_activity_typesFreeRead-onlyList the activity types CyberSight reports can contain.
dnsfilter_list_qp_methodsFreeRead-onlyList DNSFilter's QP methods dictionary.
dnsfilter_list_vpn_settings_state_typesFreeRead-onlyList the valid VPN settings state types.

[DNSFilter] Get one application by ID. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe application ID (from dnsfilter_list_applications).

[DNSFilter] Get one application category by ID. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe application category ID (from dnsfilter_list_application_categories).

[DNSFilter] Get one content category by ID. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe category ID (from dnsfilter_list_categories).

[DNSFilter] List the AI applications and websites DNSFilter recognises — the reference set behind AI-usage reporting and the starting point for building a policy around generative-AI access. Takes no parameters. Returns raw DNSFilter JSON.

[DNSFilter] List ALL applications INCLUDING deleted ones, which dnsfilter_list_applications omits. Use this when a policy references an application that no longer appears in the ordinary list. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
categoryIdsstringnonullOptional. Comma-separated application category IDs.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] List ALL content categories INCLUDING DNSFilter's internal ones, which dnsfilter_list_categories omits. Use this when a category ID appears in a report or policy but does not show up in the ordinary list. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] List the application categories — the grouping over applications, and a different axis from the CONTENT categories in dnsfilter_list_categories. Policies reference the two separately, so do not use an ID from one where the other is expected. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] List the applications DNSFilter can allow or block by name — the vocabulary the policy application tools expect. Filterable by application category. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
categoryIdsstringnonullOptional. Comma-separated application category IDs (from dnsfilter_list_application_categories). Defaults to all.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] List DNSFilter's content categories — the buckets ("Malware", "Social Media", and so on) a policy blocks by ID. Read this to turn a category name into the ID that dnsfilter_add_policy_blocked_category and the traffic reports expect. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] List the activity types CyberSight reports can contain. Read this to learn the vocabulary before filtering CyberSight data. Takes no parameters. Returns raw DNSFilter JSON.

[DNSFilter] List DNSFilter's QP methods dictionary. The vendor publishes no description or expansion for this endpoint beyond its name, so treat the response as the authority on what it contains. Takes no parameters. Returns raw DNSFilter JSON.

[DNSFilter] List the valid VPN settings state types. These are the IDs the vpn_settings_state_type_id field takes when updating an organization or a roaming client, so read this before sending one. Takes no parameters. Returns raw DNSFilter JSON.

Domain Lookups & Notes

ToolPlanAccessSummary
dnsfilter_batch_delete_domain_notesProDestructiveDelete the notes for several domains at once.
dnsfilter_batch_update_domain_notesProWriteSet notes for many domains at once on a policy, MSP or organization.
dnsfilter_bulk_lookup_domainsFreeRead-onlyLook up the classification of several FQDNs in one call.
dnsfilter_delete_domain_noteProDestructiveDelete the note recorded against one domain.
dnsfilter_get_domain_notesFreeRead-onlyRead the notes recorded against one domain on a policy, MSP or organization — the free-text record of WHY a domain was allowed or blocked.
dnsfilter_lookup_domainFreeRead-onlyLook up how DNSFilter classifies one FQDN — the domains and content categories it is associated with.
dnsfilter_suggest_threatProDestructiveSubmit an FQDN to DNSFilter for threat review, with your suggested security categories and notes.
dnsfilter_update_domain_noteProWriteSet the note recorded against one domain on a policy, MSP or organization.

[DNSFilter] Delete the notes for several domains at once. Destructive: the text for every listed domain is gone and unrecoverable. Filtering is unaffected — the domains stay on their lists. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
domainsstringyesRequired. Comma-separated domains whose notes to delete. DNSFilter declares this as a plain comma-separated string, so it is sent verbatim as a single value.
idintegeryesThe ID of that resource — a policy ID, MSP ID or organization ID to match resourceType.
resourcestringyesThe resource type the notes hang off. Accepts exactly: policies, msps, organizations.

[DNSFilter] Set notes for many domains at once on a policy, MSP or organization. Not destructive: annotation only, no filtering changes. Mind that append defaults to FALSE, which REPLACES each domain's existing note rather than adding to it. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: notes (array of {domain, note}), single_note (one note applied to every domain given), type (allow | block, defaults to allow), append (true adds to the existing note, false — the default — replaces it), organization_ids (array). DNSFilter's spec declares these as query parameters, but notes is an array of objects that no query string can represent, so the whole payload is sent as a JSON body, which its Rails backend reads identically.
idintegeryesThe ID of that resource — a policy ID, MSP ID or organization ID to match resourceType.
resourcestringyesThe resource type the notes hang off. Accepts exactly: policies, msps, organizations.

[DNSFilter] Look up the classification of several FQDNs in one call. Use this to triage a list of indicators before deciding what to block. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fqdnsstringnonullComma-separated FQDNs to look up. DNSFilter declares this one as a plain comma-separated string, so it is sent verbatim as a single value.

[DNSFilter] Delete the note recorded against one domain. Destructive in the sense that matters here: the text is gone and cannot be recovered, and it is often the only record of why a domain was allowed or blocked. Filtering itself is unaffected — the domain stays on whatever list it was on. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
domainstringyesThe domain the note is attached to, for example example.com.
idintegeryesThe ID of that resource — a policy ID, MSP ID or organization ID to match resourceType.
resourcestringyesThe resource type the notes hang off. Accepts exactly: policies, msps, organizations.

[DNSFilter] Read the notes recorded against one domain on a policy, MSP or organization — the free-text record of WHY a domain was allowed or blocked. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
domainstringyesThe domain the note is attached to, for example example.com.
idintegeryesThe ID of that resource — a policy ID, MSP ID or organization ID to match resourceType.
resourcestringyesThe resource type the notes hang off. Accepts exactly: policies, msps, organizations.

[DNSFilter] Look up how DNSFilter classifies one FQDN — the domains and content categories it is associated with. This is the tool for "why was this blocked?" and for checking a domain's reputation before allowing it. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fqdnstringnonullThe fully qualified domain name to look up, for example www.example.com.

[DNSFilter] Submit an FQDN to DNSFilter for threat review, with your suggested security categories and notes. Destructive and open-world: this LEAVES the tenant boundary — the submission goes to DNSFilter's global threat-intelligence review, where it can affect classification for other customers, and there is no operation to retract it. Look the domain up with dnsfilter_lookup_domain first. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
categoriesstringnonullOptional. Comma-separated suggested security category IDs (from dnsfilter_list_categories).
fqdnstringyesRequired. The FQDN to submit for threat review.
notesstringyesRequired. Your notes explaining why this domain should be reviewed.

[DNSFilter] Set the note recorded against one domain on a policy, MSP or organization. Not destructive: this is annotation only — it records why a domain is on an allow or block list and changes no filtering. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
domainstringyesThe domain the note is attached to, for example example.com.
fieldsJsonstringyesJSON object body. Fields: type (allow | block — which list the note belongs to), domain, note.
idintegeryesThe ID of that resource — a policy ID, MSP ID or organization ID to match resourceType.
resourcestringyesThe resource type the notes hang off. Accepts exactly: policies, msps, organizations.

MAC Addresses

ToolPlanAccessSummary
dnsfilter_create_mac_addressProWriteRegister a MAC address so a specific device gets its own policy.
dnsfilter_delete_mac_addressProDestructiveDelete a registered MAC address.
dnsfilter_get_mac_addressFreeRead-onlyGet one registered MAC address with the policy, scheduled policy and block page assigned to it.
dnsfilter_list_all_mac_addressesFreeRead-onlyList ALL registered MAC addresses, the wider counterpart to dnsfilter_list_mac_addresses.
dnsfilter_list_mac_addressesFreeRead-onlyList registered MAC addresses — per-device filtering rules keyed to a hardware address, used where a device needs its own policy without running the roaming client.
dnsfilter_update_mac_addressProWriteUpdate a registered MAC address or the policy assigned to it.

[DNSFilter] Register a MAC address so a specific device gets its own policy. Not destructive: it adds a rule and changes nothing existing, though the device starts being filtered by the assigned policy as soon as it exists. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "mac_address" key. Fields: organization_id, address (the MAC), filter_value, policy_id, scheduled_policy_id, block_page_id.

[DNSFilter] Delete a registered MAC address. Destructive: that device loses its own policy and falls back to whatever its network provides, which is usually a different rule set rather than none — the change is silent either way. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe MAC address record ID to delete (from dnsfilter_list_mac_addresses).

[DNSFilter] Get one registered MAC address with the policy, scheduled policy and block page assigned to it. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe MAC address record ID (from dnsfilter_list_mac_addresses).

[DNSFilter] List ALL registered MAC addresses, the wider counterpart to dnsfilter_list_mac_addresses. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
organizationIdsstringnonullOptional. Comma-separated organization IDs. Defaults to the authenticated user's own organization.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] List registered MAC addresses — per-device filtering rules keyed to a hardware address, used where a device needs its own policy without running the roaming client. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
organizationIdsstringnonullOptional. Comma-separated organization IDs. Defaults to the authenticated user's own organization.
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] Update a registered MAC address or the policy assigned to it. Send only the fields you want changed. Not destructive: every value can be set back. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "mac_address" key. Fields: organization_id, address, filter_value, policy_id, scheduled_policy_id, block_page_id.
idintegeryesThe MAC address record ID (from dnsfilter_list_mac_addresses).

Scheduled Policies

ToolPlanAccessSummary
dnsfilter_create_scheduled_policyProWriteCreate a scheduled policy over a set of existing policies.
dnsfilter_delete_scheduled_policyProDestructiveDelete a scheduled policy.
dnsfilter_get_scheduled_policyFreeRead-onlyGet one scheduled policy, including which policies it cycles between and the timezone the schedule is evaluated in.
dnsfilter_list_all_scheduled_policiesFreeRead-onlyList ALL scheduled policies, the wider counterpart to dnsfilter_list_scheduled_policies.
dnsfilter_list_scheduled_policiesFreeRead-onlyList scheduled policies — the time-based wrappers that swap between ordinary policies on a schedule, so a site can filter differently during and outside working hours.
dnsfilter_update_scheduled_policyProWriteUpdate a scheduled policy.

[DNSFilter] Create a scheduled policy over a set of existing policies. Not destructive: it adds a schedule and nothing uses it until a network, subnet or client is assigned to it. Set timezone deliberately — the schedule is evaluated in it, so a wrong value shifts every transition. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: name, organization_id, policy_ids (array of the policies this schedule cycles between), timezone.

[DNSFilter] Delete a scheduled policy. Destructive and irreversible — anything assigned to it stops switching policies on schedule, so the time-based filtering silently stops applying while the underlying policies survive. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe scheduled policy ID to delete (from dnsfilter_list_scheduled_policies).

[DNSFilter] Get one scheduled policy, including which policies it cycles between and the timezone the schedule is evaluated in. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe scheduled policy ID (from dnsfilter_list_scheduled_policies).

[DNSFilter] List ALL scheduled policies, the wider counterpart to dnsfilter_list_scheduled_policies. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] List scheduled policies — the time-based wrappers that swap between ordinary policies on a schedule, so a site can filter differently during and outside working hours. Paginated. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
pageNumberintegernonullOptional. 1-based page number. Omit for the first page.
pageSizeintegernonullOptional. Results per page. DNSFilter publishes no maximum; StackJack caps this at 1000.

[DNSFilter] Update a scheduled policy. Send only the fields you want changed. Not destructive as a field edit, but policy_ids REPLACES the set the schedule cycles between, and changing timezone shifts when every transition happens for everyone assigned to it. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Fields: name, organization_id, policy_ids (array — replaces the whole set), timezone.
idintegeryesThe scheduled policy ID (from dnsfilter_list_scheduled_policies).

Scheduled Reports

ToolPlanAccessSummary
dnsfilter_create_scheduled_reportProWriteCreate a recurring report that DNSFilter emails to the recipients you name.
dnsfilter_create_scheduled_report_previewProWriteGenerate a preview of what a scheduled report would contain, without creating the schedule or emailing anyone.
dnsfilter_delete_scheduled_reportProDestructiveDelete a scheduled report.
dnsfilter_get_scheduled_reportFreeRead-onlyGet one scheduled report with its frequency, contents and recipient list.
dnsfilter_get_scheduled_report_previewFreeRead-onlyRead back a scheduled report preview by ID.
dnsfilter_list_scheduled_reportsFreeRead-onlyList the scheduled reports configured for an organization — the recurring summary emails DNSFilter sends to named recipients.
dnsfilter_update_scheduled_reportProWriteUpdate a scheduled report's frequency, contents or recipients.

[DNSFilter] Create a recurring report that DNSFilter emails to the recipients you name. Marked NOT destructive deliberately, and the reason matters: it adds a configuration object whose sends are deferred and recurring rather than performing an immediate act that reaches a person, and deleting it stops the sends. Be aware all the same that every address in scheduled_report_recipients will start receiving mail on the schedule you set. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "scheduled_report" key. Fields: organization_id, frequency (monthly | bi_weekly | weekly), day_of_week, include_threat_summary, include_content_category_summary, content_categories_show_count (all_categories | top5 | top10 | top15), send_to_dashboard_users, scheduled_report_recipients (array of {email, organization}), selected_sub_orgs (array).

[DNSFilter] Generate a preview of what a scheduled report would contain, without creating the schedule or emailing anyone. Not destructive: it starts a background generation and changes no configuration. Generation is ASYNCHRONOUS — read the result with dnsfilter_get_scheduled_report_preview using the ID returned here. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "scheduled_report_preview" key. Fields: organization_id, include_threat_summary, include_content_category_summary, content_categories_show_count (all_categories | top5 | top10 | top15).

[DNSFilter] Delete a scheduled report. Destructive and irreversible — the recurring send stops and the recipient list and content settings are gone, so recipients simply stop receiving reports with no notice to them. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe scheduled report ID to delete (from dnsfilter_list_scheduled_reports).

[DNSFilter] Get one scheduled report with its frequency, contents and recipient list. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe scheduled report ID (from dnsfilter_list_scheduled_reports).

[DNSFilter] Read back a scheduled report preview by ID. Generation runs in the background, so a preview requested a moment ago may not be ready yet. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idintegeryesThe preview ID (from dnsfilter_create_scheduled_report_preview).

[DNSFilter] List the scheduled reports configured for an organization — the recurring summary emails DNSFilter sends to named recipients. Read this before changing anything, because the recipient list is the part that reaches real people. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
organizationIdintegeryesRequired. The organization whose scheduled reports to list.

[DNSFilter] Update a scheduled report's frequency, contents or recipients. Send only the fields you want changed. Not destructive: every value can be set back. Note scheduled_report_recipients REPLACES the recipient list rather than adding to it, so a partial list silently stops mail reaching the people you left out. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "scheduled_report" key. Fields: organization_id, frequency (monthly | bi_weekly | weekly), day_of_week, include_threat_summary, include_content_category_summary, content_categories_show_count (all_categories | top5 | top10 | top15), send_to_dashboard_users, scheduled_report_recipients (array of {email, organization}), selected_sub_orgs (array).
idintegeryesThe scheduled report ID (from dnsfilter_list_scheduled_reports).

Usage Metrics & Exports

ToolPlanAccessSummary
dnsfilter_create_cybersight_csv_exportProWriteStart a CSV export of a CyberSight report — activity logs, top websites, applications, categories, streaming, risky users, active clients or AI usage.
dnsfilter_get_cybersight_csv_exportFreeRead-onlyRead back a CyberSight CSV export.
dnsfilter_get_organization_usageFreeRead-onlyUsage figures for one organization over a date range — the seat and query counts behind what DNSFilter bills.
dnsfilter_get_organization_usage_detailedFreeRead-onlyUsage figures for one organization with a roaming-client count included.

[DNSFilter] Start a CSV export of a CyberSight report — activity logs, top websites, applications, categories, streaming, risky users, active clients or AI usage. Not destructive: it creates an export record and changes nothing. Two things to know: DNSFilter silently IGNORES invalid filters and column keys rather than erroring, generating the CSV from whatever remains, so a typo yields a quietly wrong export; and included_columns must be nested under cyber_sight_csv_export in the body. Read the result with dnsfilter_get_cybersight_csv_export. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Required: report_type (activity_logs | top_websites | top_applications | top_categories | top_streaming | top_risky_users | top_active_clients | top_ai_usage), start_at and end_at (ISO8601). ai_tool (all | web | app | client) is required when report_type is top_ai_usage. Column selection and organization scope go under a cyber_sight_csv_export key: {included_columns (array), organization_ids (array)}. Report filters sit at the top level and vary by report_type: msp_uuid, org_uuids, excluded_org_uuids, category_ids, user_agent_uuids, agent_local_user_uuids, weekdays_only, search_id, size, activity_type_ids, app_executable_path, app_name, app_window_title, web_full_url, web_host, threats_only, web_categories, sort_by, sort_direction. Invalid filters and columns are ignored, not rejected.

[DNSFilter] Read back a CyberSight CSV export. The id is a UUID string, not a number. Returns the export record as JSON — DNSFilter hands back an envelope carrying a link rather than CSV bytes. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
idstringyesThe export UUID (from dnsfilter_create_cybersight_csv_export). A UUID string, not a number.

[DNSFilter] Usage figures for one organization over a date range — the seat and query counts behind what DNSFilter bills. Both dates are REQUIRED and the range cannot exceed 365 days. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fromstringyesRequired. Start date in ISO8601 form, for example 2026-01-01.
idintegeryesThe organization ID (from dnsfilter_list_organizations).
tostringyesRequired. End date in ISO8601 form. The range must not exceed 365 days.

[DNSFilter] Usage figures for one organization with a roaming-client count included. This is not simply a richer version of dnsfilter_get_organization_usage: DNSFilter derives user_count and wifi_count differently here, so the two reads can legitimately disagree for the same window. Both dates are optional. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fromstringnonullOptional. Start date in ISO8601 form, for example 2026-01-01.
idintegeryesThe organization ID (from dnsfilter_list_organizations).
tostringnonullOptional. End date in ISO8601 form.

Dashboards

ToolPlanAccessSummary
dnsfilter_list_available_dashboardsFreeRead-onlyList the dashboards available to this account, including ones other users have shared into the organizations it belongs to.
dnsfilter_list_dashboardsFreeRead-onlyList the dashboards for the account this connection authenticates as, default first and the rest alphabetically.
dnsfilter_list_owned_dashboardsFreeRead-onlyList only the dashboards this account owns, as opposed to ones shared with it.

[DNSFilter] List the dashboards available to this account, including ones other users have shared into the organizations it belongs to. Wider than dnsfilter_list_dashboards. Takes no parameters. Returns raw DNSFilter JSON.

[DNSFilter] List the dashboards for the account this connection authenticates as, default first and the rest alphabetically. Takes no parameters. Returns raw DNSFilter JSON.

[DNSFilter] List only the dashboards this account owns, as opposed to ones shared with it. Takes no parameters. Returns raw DNSFilter JSON.

Account

ToolPlanAccessSummary
dnsfilter_get_current_userFreeRead-onlyRead the DNSFilter account this connection authenticates as.
dnsfilter_get_psa_integration_linkProWriteGet the redirect link that starts DNSFilter's PSA integration flow for an organization.
dnsfilter_update_current_userProWriteUpdate the profile of the account this connection authenticates as — first name, last name, phone.

[DNSFilter] Read the DNSFilter account this connection authenticates as. This is also the endpoint the connector validates credentials against, so it is the right first call when diagnosing an auth problem: it is callable by every token regardless of permissions. Takes no parameters. Returns raw DNSFilter JSON.

[DNSFilter] Update the profile of the account this connection authenticates as — first name, last name, phone. Not destructive: these are that account's own contact fields and every one can be set back. To change its password use dnsfilter_change_user_password. Returns raw DNSFilter JSON.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body, WRAPPED in a "user" key: {"user": }. Fields: first_name, last_name, phone.