- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Add-on for Microsoft Windows NOT CIM
omri_p
Engager
07-18-2019
02:50 AM
I have installed the Splunk Add-on for Microsoft Windows App on the latest 6.0 Version on Splunk Enterprise 7.3
i am ingesting DNS data using dns_debugging enabled on my DNS server.
the data is getting only of success/failure, i also do not see that under TAGS section there is a DNS tag configured under the specified app.
under the sourcetype related to that data it also does not have any DNS TAG in it.
i do not understand how the app is compatible with the CIM Model for DNS
