Getting Data In

How to index Infoblox data in Splunk?

pbernardin
Explorer

Hi.

I have seen a few posts on Infoblox > Splunk, but not much. Does anyone have infoblox data coming over to splunk successfully? I tried to point Infoblox to my Splunk heavy forwarder via udp but I am not seeing any data yet. Do I need to do via tcp? Is customization needed to be able to start seeing the data over on splunk ?

Thanks for any info,
Paul

Tags (4)
0 Karma

princemanto2580
Path Finder

Hi,

I have collected the Infoblox log in CEF format and try to forward it from Universal Forwarder. But still struggling with data on-board.

[monitor:///opt/log/infoblox01/cef.log]
disabled = 0
host = infoblox01
sourcetype = cef.log
index = infoblox

Appreciated if any suggestion or recommendation from Splunker.

0 Karma

TonyLeeVT
Builder

The TA is here: https://splunkbase.splunk.com/app/2934/#/overview
(The TA includes some panels for DNS and one for DHCP.)

Documentation is here: http://docs.splunk.com/Documentation/AddOns/latest/Infoblox/About

Enjoy!

mreynov_splunk
Splunk Employee
Splunk Employee

There have been some conf files floating around, but Splunk is about to release a TA-infoblox soon. Let me know if you still need this.

0 Karma

korstiaan
Explorer

I'm interested in this TA as well.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...