- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to index Infoblox data in Splunk?
Hi.
I have seen a few posts on Infoblox > Splunk, but not much. Does anyone have infoblox data coming over to splunk successfully? I tried to point Infoblox to my Splunk heavy forwarder via udp but I am not seeing any data yet. Do I need to do via tcp? Is customization needed to be able to start seeing the data over on splunk ?
Thanks for any info,
Paul
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi,
I have collected the Infoblox log in CEF format and try to forward it from Universal Forwarder. But still struggling with data on-board.
[monitor:///opt/log/infoblox01/cef.log]
disabled = 0
host = infoblox01
sourcetype = cef.log
index = infoblox
Appreciated if any suggestion or recommendation from Splunker.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The TA is here: https://splunkbase.splunk.com/app/2934/#/overview
(The TA includes some panels for DNS and one for DHCP.)
Documentation is here: http://docs.splunk.com/Documentation/AddOns/latest/Infoblox/About
Enjoy!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


There have been some conf files floating around, but Splunk is about to release a TA-infoblox soon. Let me know if you still need this.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm interested in this TA as well.
