All Apps and Add-ons

Why are field extractions failing for opendns:proxy sourcetype events?

piezor
Engager

Hi

I am splitting my umbrella DNS and proxy logs by sourcetype as per the instructions in the guide (opensdns:dnslogs, opendns:proxy).
However, the field extraction for the proxy logs is not working correctly.
DNS is working great and I can search by category, action, etc but these same field extractions fail for the opendns:proxy sourcetype events.

Am I missing something obvious?

1 Solution

nbertram13
Engager

I believe you may be using the incorrect sourcetype. The proxy logs need to use "opendns:proxylogs", it's referenced several times in the README with the proper sourcetype, but I see there is a typo that mentions "opendns:proxy". I will get this corrected in the README (I'm the owner/updater of this app via Hurricane Labs). Thanks for bringing this up!

View solution in original post

piezor
Engager

Updated the sourcetype to the correct format and all working correctly.

Thank you for the quick response!

0 Karma

nbertram13
Engager

I believe you may be using the incorrect sourcetype. The proxy logs need to use "opendns:proxylogs", it's referenced several times in the README with the proper sourcetype, but I see there is a typo that mentions "opendns:proxy". I will get this corrected in the README (I'm the owner/updater of this app via Hurricane Labs). Thanks for bringing this up!

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...