I have seen a few posts on Infoblox > Splunk, but not much. Does anyone have infoblox data coming over to splunk successfully? I tried to point Infoblox to my Splunk heavy forwarder via udp but I am not seeing any data yet. Do I need to do via tcp? Is customization needed to be able to start seeing the data over on splunk ?
Thanks for any info,
I have collected the Infoblox log in CEF format and try to forward it from Universal Forwarder. But still struggling with data on-board.
disabled = 0
host = infoblox01
sourcetype = cef.log
index = infoblox
Appreciated if any suggestion or recommendation from Splunker.
The TA is here: https://splunkbase.splunk.com/app/2934/#/overview
(The TA includes some panels for DNS and one for DHCP.)
Documentation is here: http://docs.splunk.com/Documentation/AddOns/latest/Infoblox/About