All Apps and Add-ons

Active Directory DNS logs - extract domain name without periods

daniel_augustyn
Contributor

I've been trying to extract domains from AD DNS logs with the following rex and it's not really working well:

[win]
SEDCMD = s/(\d+)/./g

I am still getting leading and trailing periods, for example:

.www.google.com.

The raw logs has parentheses with number of letters in it.
(3)www(6)google(3)com

Any other idea how to do it right?

1 Solution

dwaddle
SplunkTrust
SplunkTrust

This is kind-of a non-answer to your question. But, you might find more success using something like the Splunk App for Stream to pick up DNS data. You'll get nice, clean JSON events with requests and responses and no Windows log silliness..

View solution in original post

gerardo_maya
Splunk Employee
Splunk Employee

Hello Daniel, 

I found that using the command replace you can create a calculated field called dest.

| eval dest = replace(replace(dnsQuery,"\(\d+\)","."),"^\.|\.$","")

On the first replace you eliminate all the number rounded by parenthesis, and on the other replace you eliminate the first and the last period.

So on Cloud you only need to create a calculated field and put the function replace, just like this

replace(replace(dnsQuery,"\(\d+\)","."),"^\.|\.$","")

I hope it helps other Splunkers to solve this issue or other similar. 

Tags (3)
0 Karma

woodcock
Esteemed Legend

Your question is phrased very poorly so I cannot begin to answer. You say "capture" but then you are actually using SEDMCD which does not "capture", it actually "modifies by replacing". Please clearly restate what you would like, including a COMPLETE example with a fake event and desired outcome mockup.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

This is kind-of a non-answer to your question. But, you might find more success using something like the Splunk App for Stream to pick up DNS data. You'll get nice, clean JSON events with requests and responses and no Windows log silliness..

daniel_augustyn
Contributor

Thank you, I would look into it.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...