All Apps and Add-ons

Why are field extractions failing for opendns:proxy sourcetype events?

piezor
Engager

Hi

I am splitting my umbrella DNS and proxy logs by sourcetype as per the instructions in the guide (opensdns:dnslogs, opendns:proxy).
However, the field extraction for the proxy logs is not working correctly.
DNS is working great and I can search by category, action, etc but these same field extractions fail for the opendns:proxy sourcetype events.

Am I missing something obvious?

1 Solution

nbertram13
Engager

I believe you may be using the incorrect sourcetype. The proxy logs need to use "opendns:proxylogs", it's referenced several times in the README with the proper sourcetype, but I see there is a typo that mentions "opendns:proxy". I will get this corrected in the README (I'm the owner/updater of this app via Hurricane Labs). Thanks for bringing this up!

View solution in original post

piezor
Engager

Updated the sourcetype to the correct format and all working correctly.

Thank you for the quick response!

0 Karma

nbertram13
Engager

I believe you may be using the incorrect sourcetype. The proxy logs need to use "opendns:proxylogs", it's referenced several times in the README with the proper sourcetype, but I see there is a typo that mentions "opendns:proxy". I will get this corrected in the README (I'm the owner/updater of this app via Hurricane Labs). Thanks for bringing this up!

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...