<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Add-on for Infoblox compatibility with Splunk &amp;amp; ES version 10 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/761986#M120642</link>
    <description>&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2934" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/2934&lt;/A&gt;&amp;nbsp;is it compatible with Splunk enterprise &amp;amp; ES 10.0.4 even though it's archived. Not seeing the following fields&amp;nbsp;&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&lt;STRONG&gt;Data Model Network_Resolution Fields:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;DNS.src&lt;/P&gt;&lt;P&gt;DNS.src_category&lt;/P&gt;&lt;P&gt;DNS.message&lt;/P&gt;&lt;P&gt;DNS.reply_code&lt;/P&gt;&lt;P&gt;DNS.record_type&lt;/P&gt;&lt;P&gt;DNS.query&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jun 2026 18:33:41 GMT</pubDate>
    <dc:creator>USA69</dc:creator>
    <dc:date>2026-06-29T18:33:41Z</dc:date>
    <item>
      <title>Splunk Add-on for Infoblox compatibility with Splunk &amp; ES version 10</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/761986#M120642</link>
      <description>&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2934" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/2934&lt;/A&gt;&amp;nbsp;is it compatible with Splunk enterprise &amp;amp; ES 10.0.4 even though it's archived. Not seeing the following fields&amp;nbsp;&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&lt;STRONG&gt;Data Model Network_Resolution Fields:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;DNS.src&lt;/P&gt;&lt;P&gt;DNS.src_category&lt;/P&gt;&lt;P&gt;DNS.message&lt;/P&gt;&lt;P&gt;DNS.reply_code&lt;/P&gt;&lt;P&gt;DNS.record_type&lt;/P&gt;&lt;P&gt;DNS.query&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2026 18:33:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/761986#M120642</guid>
      <dc:creator>USA69</dc:creator>
      <dc:date>2026-06-29T18:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Infoblox compatibility with Splunk &amp; ES version 10</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/761993#M120643</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/317458"&gt;@USA69&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a Splunk supported addon, therefore I would recommend raising a support case with these details and you should hopefully get this raised directly to the correct team internally.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;STRONG&gt;Did this answer help you? If so, please consider&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2026 21:58:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/761993#M120643</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2026-06-29T21:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Infoblox compatibility with Splunk &amp; ES version 10</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/762011#M120646</link>
      <description>&lt;P&gt;The addon lists the DNS datamodel as one supported for infoblox:dns sourcetype so I would expect it to work.&lt;/P&gt;&lt;P&gt;Having said that - have you verified that your input side is properly configured? And that the source is properly configured to emit properly formatted events? (I don't have much experience with this particular solution but often add-ons rely on some specific configurations on the source side; or sometimes there is something "in between" that messes up the events so they reach Splunk in a different format than add-on creators assumed).&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2026 17:46:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/762011#M120646</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-06-30T17:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Infoblox compatibility with Splunk &amp; ES version 10</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/762030#M120651</link>
      <description>&lt;P&gt;The add-on does not have inputs.conf configured on the default. And it's sending the logs via syslog-ng. Do I still need to create the inputs.conf on the local folder? And will appreciate if you can very if this is the correct configuration for inputs.conf below&lt;/P&gt;&lt;P&gt;[udp://514]&lt;BR /&gt;connection_host = ip&lt;BR /&gt;sourcetype = infoblox:syslog&lt;BR /&gt;index = infoblox&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 12:57:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/762030#M120651</guid>
      <dc:creator>USA69</dc:creator>
      <dc:date>2026-07-01T12:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Infoblox compatibility with Splunk &amp; ES version 10</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/762034#M120653</link>
      <description>&lt;P&gt;OK. If you're receiving your syslogs through an external component, make sure the resulting combined configuration of the ingesting side doesn't modify the events in a way that they don't match the assumed format. You don't have to define additional input on your Splunk box directly.&lt;/P&gt;&lt;P&gt;Are your events correctly sourcetyped? As far as I remember, the addon does some sourcetype-casting depending on the type of events you're receiving so even though your sourcetype should be configured as infoblox:syslog in your syslog-ng configuration&amp;nbsp; (or - if you're using intermediate files - your file inputs reading the files must set that sourcetype) but after ingestion the events should be indexed as - in your case - infoblox:dns sourcetype. Does it match your situation?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 15:09:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/762034#M120653</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-07-01T15:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Infoblox compatibility with Splunk &amp; ES version 10</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/762044#M120656</link>
      <description>&lt;P&gt;It was configured through Cribl to send the logs to Splunk. the sourcetype is&amp;nbsp;infoblox:dns&lt;/P&gt;&lt;P&gt;source is infoblox&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2026 14:01:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/762044#M120656</guid>
      <dc:creator>USA69</dc:creator>
      <dc:date>2026-07-02T14:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Infoblox compatibility with Splunk &amp; ES version 10</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/762059#M120657</link>
      <description>&lt;P&gt;With that much information can't tell anything more. You have to check whether Cribl does something to your events (we don't know that), whether the events fit the extractions defined in the TA (can use regex101 for that).&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2026 16:10:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/762059#M120657</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-07-02T16:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Infoblox compatibility with Splunk &amp; ES version 10</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/762089#M120659</link>
      <description>&lt;P&gt;Thanks for the update&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2026 11:13:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Infoblox-compatibility-with-Splunk-amp-ES/m-p/762089#M120659</guid>
      <dc:creator>USA69</dc:creator>
      <dc:date>2026-07-06T11:13:46Z</dc:date>
    </item>
  </channel>
</rss>

