<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there an add-on to monitor and parse DNS logs from Windows 2012 R2 DNS servers? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-there-an-add-on-to-monitor-and-parse-DNS-logs-from-Windows/m-p/246837#M28057</link>
    <description>&lt;P&gt;download splunk app for windows infrastructure &lt;A href="https://splunkbase.splunk.com/app/1680/"&gt;https://splunkbase.splunk.com/app/1680/&lt;/A&gt; then dive to appserver then to addons then you will find DNS TA and other usefull once ....&lt;/P&gt;

&lt;P&gt;good luck &lt;/P&gt;</description>
    <pubDate>Thu, 12 May 2016 01:00:44 GMT</pubDate>
    <dc:creator>mosman_splunk</dc:creator>
    <dc:date>2016-05-12T01:00:44Z</dc:date>
    <item>
      <title>Is there an add-on to monitor and parse DNS logs from Windows 2012 R2 DNS servers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-there-an-add-on-to-monitor-and-parse-DNS-logs-from-Windows/m-p/246836#M28056</link>
      <description>&lt;P&gt;I am looking for TA for DNS logs from 2012 R2 DNS servers. Would TA-DNSServer-NT6 work? I believe TA-DNSServer-NT6 was created for Windows 2008 R2 DNS Services. &lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 00:43:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-there-an-add-on-to-monitor-and-parse-DNS-logs-from-Windows/m-p/246836#M28056</guid>
      <dc:creator>daniel_augustyn</dc:creator>
      <dc:date>2016-05-12T00:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Is there an add-on to monitor and parse DNS logs from Windows 2012 R2 DNS servers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-there-an-add-on-to-monitor-and-parse-DNS-logs-from-Windows/m-p/246837#M28057</link>
      <description>&lt;P&gt;download splunk app for windows infrastructure &lt;A href="https://splunkbase.splunk.com/app/1680/"&gt;https://splunkbase.splunk.com/app/1680/&lt;/A&gt; then dive to appserver then to addons then you will find DNS TA and other usefull once ....&lt;/P&gt;

&lt;P&gt;good luck &lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 01:00:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-there-an-add-on-to-monitor-and-parse-DNS-logs-from-Windows/m-p/246837#M28057</guid>
      <dc:creator>mosman_splunk</dc:creator>
      <dc:date>2016-05-12T01:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: Is there an add-on to monitor and parse DNS logs from Windows 2012 R2 DNS servers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-there-an-add-on-to-monitor-and-parse-DNS-logs-from-Windows/m-p/246838#M28058</link>
      <description>&lt;P&gt;TA-DNSServer-NT6 is for 2008 and later, so it should be used for 2012 R2.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/MSApp/1.2.1/MSInfra/DownloadandconfiguretheSplunkAdd-onsforWindowsDNS"&gt;http://docs.splunk.com/Documentation/MSApp/1.2.1/MSInfra/DownloadandconfiguretheSplunkAdd-onsforWindowsDNS&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 14:57:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-there-an-add-on-to-monitor-and-parse-DNS-logs-from-Windows/m-p/246838#M28058</guid>
      <dc:creator>spayneort</dc:creator>
      <dc:date>2016-05-12T14:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: Is there an add-on to monitor and parse DNS logs from Windows 2012 R2 DNS servers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-there-an-add-on-to-monitor-and-parse-DNS-logs-from-Windows/m-p/246839#M28059</link>
      <description>&lt;P&gt;This doesn't seem to work for 2012 DNS Analytical logs. I have the following monitoring stanza but it's throwing an error. &lt;BR /&gt;
[WinEventLog://Microsoft-Windows-DNSServer/Analytical]&lt;/P&gt;

&lt;P&gt;'WinEventLogChannel::subscribeToEvtChannel: Could not subscribe to Windows Event Log channel ‘microsoft-windows-dnsserver/analytical errorCode=15009’&lt;/P&gt;

&lt;P&gt;&lt;A href="https://technet.microsoft.com/en-us/library/dn800669.aspx#dbug"&gt;https://technet.microsoft.com/en-us/library/dn800669.aspx#dbug&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 22:23:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-there-an-add-on-to-monitor-and-parse-DNS-logs-from-Windows/m-p/246839#M28059</guid>
      <dc:creator>rajbir1</dc:creator>
      <dc:date>2017-01-24T22:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is there an add-on to monitor and parse DNS logs from Windows 2012 R2 DNS servers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-there-an-add-on-to-monitor-and-parse-DNS-logs-from-Windows/m-p/246840#M28060</link>
      <description>&lt;P&gt;Did you find a solution for reading the Microsoft-Windows-DNSServer/Analytical logs?    It's my understanding from this article that the analytical log can't be read "online" if circular logging is enabled.&lt;BR /&gt;
&lt;A href="https://support.microsoft.com/en-us/help/2488055/error-when-enabling-analytic-or-debug-event-log"&gt;Error when enabling Analytic or Debug event log: "The requested operation cannot be performed over an enabled direct channel&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;One solution might be to switch the event log to manual clearing and configure the Splunk add-on to do that log clearing.  I'm not sure if that's a feature of the add-on.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2018 19:30:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-there-an-add-on-to-monitor-and-parse-DNS-logs-from-Windows/m-p/246840#M28060</guid>
      <dc:creator>hughkelley</dc:creator>
      <dc:date>2018-04-17T19:30:07Z</dc:date>
    </item>
  </channel>
</rss>

