<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ingesting DNS Server logs in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Ingesting-DNS-Server-logs/m-p/389870#M4187</link>
    <description>&lt;P&gt;If you want to use different sourcetype for DNS logs and want to utilize '&lt;STRONG&gt;Splunk Add-on for Windows&lt;/STRONG&gt;' for data normalization as per CIM, you can clone the configurations of 'wineventlog' sourcetype in '&lt;STRONG&gt;props.conf&lt;/STRONG&gt;' and rename the sourcetype to 'dns'.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Reference:&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/WindowsAddOn/6.0.0/User/Configuration"&gt;https://docs.splunk.com/Documentation/WindowsAddOn/6.0.0/User/Configuration&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 03 Aug 2019 18:04:10 GMT</pubDate>
    <dc:creator>jawaharas</dc:creator>
    <dc:date>2019-08-03T18:04:10Z</dc:date>
    <item>
      <title>Ingesting DNS Server logs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Ingesting-DNS-Server-logs/m-p/389869#M4186</link>
      <description>&lt;P&gt;I would like to forward DNS events from my DNS server with a UF that is monitoring the dns.log debug output.&lt;BR /&gt;
i am already forwarding WIndows Events under sourcetype=wineventlog&lt;BR /&gt;
based on &lt;A href="https://docs.splunk.com/Documentation/WindowsAddOn/6.0.0/User/SourcetypesandCIMdatamodelinfo"&gt;https://docs.splunk.com/Documentation/WindowsAddOn/6.0.0/User/SourcetypesandCIMdatamodelinfo&lt;/A&gt; &lt;BR /&gt;
DNS Logs would also need to be under the same sourcetype name in order for the add on &lt;A href="https://splunkbase.splunk.com/app/742/"&gt;https://splunkbase.splunk.com/app/742/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;
to normalize the events&lt;BR /&gt;
i do not wish to use the same sourcetype name for the win events and for the DNS&lt;BR /&gt;
what am i missing?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2019 20:39:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Ingesting-DNS-Server-logs/m-p/389869#M4186</guid>
      <dc:creator>omri_p</dc:creator>
      <dc:date>2019-07-16T20:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Ingesting DNS Server logs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Ingesting-DNS-Server-logs/m-p/389870#M4187</link>
      <description>&lt;P&gt;If you want to use different sourcetype for DNS logs and want to utilize '&lt;STRONG&gt;Splunk Add-on for Windows&lt;/STRONG&gt;' for data normalization as per CIM, you can clone the configurations of 'wineventlog' sourcetype in '&lt;STRONG&gt;props.conf&lt;/STRONG&gt;' and rename the sourcetype to 'dns'.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Reference:&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/WindowsAddOn/6.0.0/User/Configuration"&gt;https://docs.splunk.com/Documentation/WindowsAddOn/6.0.0/User/Configuration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Aug 2019 18:04:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Ingesting-DNS-Server-logs/m-p/389870#M4187</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2019-08-03T18:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: Ingesting DNS Server logs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Ingesting-DNS-Server-logs/m-p/389871#M4188</link>
      <description>&lt;P&gt;@omri_p &lt;BR /&gt;
Can you upvote and accept the answer if it's helped you? Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 05:10:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Ingesting-DNS-Server-logs/m-p/389871#M4188</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2019-08-07T05:10:31Z</dc:date>
    </item>
  </channel>
</rss>

