Yes, there’s noise you can filter out, but you need to log things!
A client I work with finally implemented DNS resolver logs and we found unmanaged devices (that’s its own headache) that were requesting domains ranging from guns to porn and malware and everything in between.
Due to the already sparse logging, we didn’t know about it until the DNS logs started coming in.
Now someone in HR gets to talk to some users about proper conduct in the workplace and the BYOD policy is getting reviewed.
Source: r/cybersecurity · by /u/pcx436