<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blacklisting DNS queries with nullQueue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428756#M75133</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;You must escape the  [&lt;STRONG&gt;.&lt;/STRONG&gt;] character:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[bl_subdom_domain01_com]
REGEX= query=subdom\.domain01\.com
DEST_KEY=queue
FORMAT=nullQueue

[bl_domain02_com]
REGEX= query=domain02\.com
DEST_KEY=queue
FORMAT=nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope it helps&lt;/P&gt;</description>
    <pubDate>Tue, 06 Aug 2019 19:10:16 GMT</pubDate>
    <dc:creator>jaime_ramirez</dc:creator>
    <dc:date>2019-08-06T19:10:16Z</dc:date>
    <item>
      <title>Blacklisting DNS queries with nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428755#M75132</link>
      <description>&lt;P&gt;I am attempting to blacklist DNS queries  using nullQueue.&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# Blacklist domains
[msad:nt6:dns]
TRANSFORMS-blacklistdomain01 = bl_subdom_domain01_com
TRANSFORMS-blacklistdomain02 = bl_domain02_com
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[bl_subdom_domain01_com]
REGEX=query=subdom.domain01.com
DEST_KEY=queue
FORMAT=nullQueue

[bl_domain02_com]
REGEX=query=domain02.com
DEST_KEY=queue
FORMAT=nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This does not work! Is there something wrong with the syntax I've used?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 11:17:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428755#M75132</guid>
      <dc:creator>geoffmx</dc:creator>
      <dc:date>2019-08-06T11:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting DNS queries with nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428756#M75133</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;You must escape the  [&lt;STRONG&gt;.&lt;/STRONG&gt;] character:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[bl_subdom_domain01_com]
REGEX= query=subdom\.domain01\.com
DEST_KEY=queue
FORMAT=nullQueue

[bl_domain02_com]
REGEX= query=domain02\.com
DEST_KEY=queue
FORMAT=nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope it helps&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 19:10:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428756#M75133</guid>
      <dc:creator>jaime_ramirez</dc:creator>
      <dc:date>2019-08-06T19:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting DNS queries with nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428757#M75134</link>
      <description>&lt;P&gt;I'm not having any luck with this. The nullQueue method did not work. I've even tried blacklisting the domain in inputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[MSAD:NT6:DNS]
disabled=false
index=msad
blacklist1 = query="domain01\.com"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Escaping the [.] character does not seem to have any effect. &lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 10:18:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428757#M75134</guid>
      <dc:creator>geoffmx</dc:creator>
      <dc:date>2019-08-22T10:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting DNS queries with nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428758#M75135</link>
      <description>&lt;P&gt;dyude @geoffmx ,&lt;/P&gt;

&lt;P&gt;Can you try this,&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[msad:nt6:dns]
TRANSFORMS-set= domain1,domain2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[domain1]
REGEX = query\=subdom\.domain01\.com
DEST_KEY = queue
FORMAT = nullQueue

[domain2]
REGEX = query\=domain02\.com
DEST_KEY = queue
FORMAT = nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Llet me know if it works for you!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 17:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428758#M75135</guid>
      <dc:creator>vinod94</dc:creator>
      <dc:date>2019-08-22T17:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting DNS queries with nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428759#M75136</link>
      <description>&lt;P&gt;Is your sourcetype of &lt;CODE&gt;msad:nt6:dns&lt;/CODE&gt; correct in props?&lt;/P&gt;

&lt;P&gt;Here is what I set up yesterday:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;me@local$ cat props.conf
[WebViewIIS]
TRANSFORMS-set = setnull_webview,setparsing_webview
me@local$ cat transforms.conf
[setnull_webview]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue

[setparsing_webview]
REGEX = (?i)mycompany-domain
DEST_KEY = queue
FORMAT = indexQueue
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 22 Aug 2019 18:43:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428759#M75136</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2019-08-22T18:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting DNS queries with nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428760#M75137</link>
      <description>&lt;P&gt;Yes, I believe the sourcetype is correct. &lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/DCDNSAddOn/1.0.2/TA-WindowsDNS/Sourcetypes"&gt;https://docs.splunk.com/Documentation/DCDNSAddOn/1.0.2/TA-WindowsDNS/Sourcetypes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 05:34:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428760#M75137</guid>
      <dc:creator>geoffmx</dc:creator>
      <dc:date>2019-08-23T05:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting DNS queries with nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428761#M75138</link>
      <description>&lt;P&gt;None of this works, unfortunately. I wonder if I am editing the .conf files in the correct location. &lt;/P&gt;

&lt;P&gt;In the splunk etc directory, there are two folders for DNS:&lt;/P&gt;

&lt;P&gt;$SPLUNK_HOME/etc/apps/TA-DNSServer-NT6/local, and &lt;BR /&gt;
$SPLUNK_HOME/etc/deployment-apps/Splunk_TA_microsoft_dns/local&lt;/P&gt;

&lt;P&gt;Is there a way to determine the right app directory for a given sourcetype?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428761#M75138</guid>
      <dc:creator>geoffmx</dc:creator>
      <dc:date>2020-09-30T01:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting DNS queries with nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428762#M75139</link>
      <description>&lt;P&gt;etc/deployment-apps is only for apps that you are pushing out to ufs from a deployment server&lt;/P&gt;

&lt;P&gt;so you need to be doing this in the etc/apps directory on your indexer or search head; for your question specifically that's indexer&lt;/P&gt;

&lt;P&gt;the directory inside of /etc/apps doesn't matter as much, as long as it's in a local directory, since it's a configuration hierarchy (see btool)&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 17:26:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428762#M75139</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2019-08-23T17:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting DNS queries with nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428763#M75140</link>
      <description>&lt;P&gt;Since you are dropping the file before indexing, your regex needs to match the syntax of the raw event data, not the formatted data.&lt;/P&gt;

&lt;P&gt;So if your domain you want to drop is company.com, this will look something like this in the logs:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(3)company(2)com(0)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So you may want to have a regex like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;\(\d\)company\(\d\)com
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 02 Sep 2019 02:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-DNS-queries-with-nullQueue/m-p/428763#M75140</guid>
      <dc:creator>jeremyhagand61</dc:creator>
      <dc:date>2019-09-02T02:47:17Z</dc:date>
    </item>
  </channel>
</rss>

