Add a Policy filter to the Query Log to help administrators identify which policy is responsible for a given filtering decision.
Problem:
When troubleshooting filtering behavior, administrators need to isolate queries handled by a specific policy. The Query Log currently has no way to filter by policy, requiring manual review of large volumes of log data to find relevant entries.
Who's Affected:
Administrators and security teams managing multiple policies across networks, devices, or user groups.
Desired Outcome:
  • A Policy filter is available in the Query Log, allowing administrators to view only queries resolved under a specific policy
  • Results update dynamically alongside existing filters (network, device, date range, etc.)
  • Reduces time-to-resolution for policy troubleshooting workflows