All Apps and Add-ons

Infoblox TA not extracting response code

bowesmana
SplunkTrust
SplunkTrust

Using version 2.1 of the infoblox TA, it is not extracting all the fields correctly. The named_message field seems to have the text 'view 2:' in it, which for the dns_response extraction will extract this to the dns_view field.

However, it only does this for the single extraction, but there are a number of other extractions that do not have this dns_view field and therefore none of the extractions work. In particular, the reply_code never gets set, so this results in all reply_codes in the Network Resolution datamodel ending up as 'unknown'.

Has anyone seen this behaviour before and know what the solution might be?

 

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...