All Apps and Add-ons

How to use Splunk Stream to send DNS analytic logs from DNS server to Splunk?

tonyxavierj
Engager

How to use Splunk Stream and send DNS analytic logs from DNS server to Splunk?
Splunk is running on Windows Server 2012 and DNS server is also 2012
What I am trying to achieve is detect malicious DNS traffic
There is no proper documentation on this product

0 Karma
1 Solution

gjanders
SplunkTrust
SplunkTrust

Perhaps you can send the documentation team some constructive feedback if you cannot find what you want?

Splunk Stream™ Installation and Configuration Manual , DNS is a supported protocol, if you download the PDF and read through it:

Stream data capture configuration
basics Use the Configure Streams UI
inside Splunk App for Stream
(splunk_app_stream) to configure the
specific network data protocols (such
as http, tcp, dns, pop3, smtp and so
on) that you want the streamfwd binary
to capture

Basically you install the TA somewhere, the documentation will state about winpcap been installed (I've only used stream on Linux so you will need to check the requirements).
You point the TA to where you are hosting the stream app, then you use the stream app to remotely configure the TA to forward DNS data.

View solution in original post

0 Karma

gjanders
SplunkTrust
SplunkTrust

Perhaps you can send the documentation team some constructive feedback if you cannot find what you want?

Splunk Stream™ Installation and Configuration Manual , DNS is a supported protocol, if you download the PDF and read through it:

Stream data capture configuration
basics Use the Configure Streams UI
inside Splunk App for Stream
(splunk_app_stream) to configure the
specific network data protocols (such
as http, tcp, dns, pop3, smtp and so
on) that you want the streamfwd binary
to capture

Basically you install the TA somewhere, the documentation will state about winpcap been installed (I've only used stream on Linux so you will need to check the requirements).
You point the TA to where you are hosting the stream app, then you use the stream app to remotely configure the TA to forward DNS data.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...