Hi All,
I have recently ingested Cisco Umbrella logs into Splunk Cloud (8.1.2) and everything seems to be working fine, expect for the Network Resolution DNS data model. When I try to accelerate the model or pivot, I obtain the following errrors:
I reviewed the search.log but don't see anything related to causing the issue. Has anyone experienced or solved this before?
Cheers
Just encountered the same error.
Fixed by downloading the CIM app from Splunkbase and extracting the cim_dns_reply_codes2.csv.default file (from Splunk_SA_CIM/lookups/) , saving it as cim_dns_reply_codes2.csv and then uploading it back to the CIM app on our instance.
For some reason the CSV is there in the app as cim_dns_reply_codes2.csv.default which Splunk doesn't seem to recognise as a valid CSV.
Rebuilding the Network_Resolution data model and seems to be working now.