Is there a way to indicate in the reporting what process or task is making a DNS request? I'm able to figure some of them out, such as Aliases containing old machine names, but often I have no idea why a query is happening.
In that same vein, what would be causing all of the arpa lookups? I can see them being used if I have resolve hostnames turned on for something like the live firewall view, but outside of that I'm not sure why there are so many reverse lookups.