All Apps and Add-ons
Highlighted

Splunk for DNS: How can I update the blacklist.csv file?

New Member

I was wondering, how can I update the blacklist.csv file? What was the initial feed and how can I update this periodically? This data changes almost everyday, so it would be nice if this is list is up to date.

thx.
Eddie

0 Karma
Highlighted

Re: Splunk for DNS: How can I update the blacklist.csv file?

Splunk Employee
Splunk Employee
  1. <> | outputlookup blacklistlookupname
  2. save this as a saved search and have it run on a schedule

http://docs.splunk.com/Documentation/Splunk/6.3.1/SearchReference/Outputlookup

0 Karma
Highlighted

Re: Splunk for DNS: How can I update the blacklist.csv file?

New Member

I was actually wondering where I can find the initial feed. No the csv is a static file but I think fot he best use of this app you should update this file at least once a day to get the latest acurate data. So if i know the actual feed I can download it and update it by a scheduled job.

0 Karma