Hello Splunkers,
Has any one worked on infoblox DHCP and DNS data sourctypes , i see the src , srcport, dstport, dst fields are flipping with events information. Any one had made any adjustments in TA side ? Any suggestions.
What is the sourcetype you used in syslog monitor inputs , it should be "infoblox:file"
You need to install Splunk_TA_infoblox on your HF/Indexers, hope this will fix.
Hey im beyond that source type level, InfoBlox have predefined 2 sourcetypes infoblox:dhs and DNS,
DNS had issues flip when you getting response and request logs.