- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
chris_barrett

SplunkTrust
04-23-2019
08:22 PM
The search that drives the "Live Data"/"Must have firewall data" test for the "Sources Sending a High Volume of DNS Traffic" example is missing the 'tag=' from in front of 'network'.
Noticed in version 2.4.1 - I'm not sure if it affects earlier versions too.
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
David

Splunk Employee
04-24-2019
04:51 AM
Fixed in dev (and verified it wasn't copy-pasted anywhere)! This will be shipped in SSE 2.4.2, thank you!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
David

Splunk Employee
04-24-2019
04:51 AM
Fixed in dev (and verified it wasn't copy-pasted anywhere)! This will be shipped in SSE 2.4.2, thank you!
