<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Request in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/DNS-Request/m-p/692880#M10280</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cant show my logs because of privacy&amp;nbsp;issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;but for example:&lt;/P&gt;&lt;P&gt;in INDEX 1&amp;nbsp;&lt;/P&gt;&lt;P&gt;src=1.1.1.1 query=dns.com direcrion=&amp;nbsp; snd&lt;/P&gt;&lt;P&gt;INDEX2&lt;/P&gt;&lt;P&gt;domain = dns.com category= education websit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2024 13:20:36 GMT</pubDate>
    <dc:creator>NoamP</dc:creator>
    <dc:date>2024-07-10T13:20:36Z</dc:date>
    <item>
      <title>DNS Request</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/DNS-Request/m-p/692858#M10278</link>
      <description>&lt;P&gt;Hey,&lt;BR /&gt;I would love to get help&lt;BR /&gt;I want to build a query to be a rule that will monitor DNS requests&lt;BR /&gt;I work with two INDEXES in one of them (INDEX1) I need the following fields&lt;BR /&gt;src , query , direction and I want that according to the results I got from this 1INDEX the second 2INDEX will take the query field and check what category it falls under&lt;BR /&gt;In the second (2INDEX) the query field is equivalent to the DOMAIN field and the category field does not exist in INDEX1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 08:31:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/DNS-Request/m-p/692858#M10278</guid>
      <dc:creator>NoamP</dc:creator>
      <dc:date>2024-07-10T08:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Request</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/DNS-Request/m-p/692868#M10279</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/269822"&gt;@NoamP&lt;/a&gt;&amp;nbsp;.. i assume that the logs are already onboarded to Splunk indexer.&amp;nbsp; (suggest us how do you onboarded the logs pls)&lt;/P&gt;&lt;P&gt;could you pls show us some sample logs pls, then the SPL query can be created easily.. thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 10:13:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/DNS-Request/m-p/692868#M10279</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-07-10T10:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Request</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/DNS-Request/m-p/692880#M10280</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cant show my logs because of privacy&amp;nbsp;issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;but for example:&lt;/P&gt;&lt;P&gt;in INDEX 1&amp;nbsp;&lt;/P&gt;&lt;P&gt;src=1.1.1.1 query=dns.com direcrion=&amp;nbsp; snd&lt;/P&gt;&lt;P&gt;INDEX2&lt;/P&gt;&lt;P&gt;domain = dns.com category= education websit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 13:20:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/DNS-Request/m-p/692880#M10280</guid>
      <dc:creator>NoamP</dc:creator>
      <dc:date>2024-07-10T13:20:36Z</dc:date>
    </item>
  </channel>
</rss>

