Getting Data In

Splunk Add-on for Microsoft Windows NOT CIM

omri_p
Engager

I have installed the Splunk Add-on for Microsoft Windows App on the latest 6.0 Version on Splunk Enterprise 7.3
i am ingesting DNS data using dns_debugging enabled on my DNS server.
the data is getting only of success/failure, i also do not see that under TAGS section there is a DNS tag configured under the specified app.
under the sourcetype related to that data it also does not have any DNS TAG in it.

i do not understand how the app is compatible with the CIM Model for DNS

Tags (3)
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...