How to generate a search which will indicate which hosts are communicating with two old DNS servers?

Hi All,

I need to generate a search and a report which will indicate which hosts are communicating with 2 old DNS servers i need to decommission. I am a Splunk noob and I did not find the data needed easily so I figured I will ask for help.

Your input is much appreciated and many thanks!


hello there,
if you dont have the data in splunk, you will not be able to create the report ...
bring the data from those DNS servers (or all other servers) and search for the DNS server names. check which "host" field is associated with them. that will be a good start imho/

hope it helps a little

