https://splunkbase.splunk.com/app/2934 is it compatible with Splunk enterprise & ES 10.0.4 even though it's archived. Not seeing the following fields
in Data Model Network_Resolution Fields:
DNS.src
DNS.src_category
DNS.message
DNS.reply_code
DNS.record_type
DNS.query
Hi @USA69
This is a Splunk supported addon, therefore I would recommend raising a support case with these details and you should hopefully get this raised directly to the correct team internally.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing.