Getting Data In

How to index Infoblox data in Splunk?

pbernardin
Explorer

Hi.

I have seen a few posts on Infoblox > Splunk, but not much. Does anyone have infoblox data coming over to splunk successfully? I tried to point Infoblox to my Splunk heavy forwarder via udp but I am not seeing any data yet. Do I need to do via tcp? Is customization needed to be able to start seeing the data over on splunk ?

Thanks for any info,
Paul

Tags (4)
0 Karma

princemanto2580
Path Finder

Hi,

I have collected the Infoblox log in CEF format and try to forward it from Universal Forwarder. But still struggling with data on-board.

[monitor:///opt/log/infoblox01/cef.log]
disabled = 0
host = infoblox01
sourcetype = cef.log
index = infoblox

Appreciated if any suggestion or recommendation from Splunker.

0 Karma

TonyLeeVT
Builder

The TA is here: https://splunkbase.splunk.com/app/2934/#/overview
(The TA includes some panels for DNS and one for DHCP.)

Documentation is here: http://docs.splunk.com/Documentation/AddOns/latest/Infoblox/About

Enjoy!

mreynov_splunk
Splunk Employee
Splunk Employee

There have been some conf files floating around, but Splunk is about to release a TA-infoblox soon. Let me know if you still need this.

0 Karma

korstiaan
Explorer

I'm interested in this TA as well.

0 Karma
Get Updates on the Splunk Community!

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...

Splunk SOAR Now Available on Google Cloud Platform

We’re excited to announce that Splunk SOAR is now natively available as a SaaS solution on Google Cloud ...