I have configured the Pi Hole TA, App and CIM and when I open the dashboards it is empty with No Results Found.
I can run this search and it shows the count in the thousands:
| tstats local=f summariesonly=t allow_old_summaries=t count from datamodel=Network_Resolution.DNS
When I run sourcetype=pihole, events come back, but no fields are listed.
What did I do wrong?
Look here: https://github.com/ZachChristensen28/TA-pihole_dns
Create a new file: /etc/dnsmasq.d/02-pihole-splunk.conf. Add log-queries=extra to the file. save and close the file Restart pi-hole with pihole restartdns
I had to do that for the extractions to begin working correctly as well.