Getting Data In

Why is DNS lookup failing during indexing for 2 hosts?

Path Finder

I just moved my Splunk indexer from one server to another. A few bumps in the road, but everything seems to be working now, except for that fact that two hosts will not resolve in DNS, so Splunk is indexing them as IP addresses instead. They are located on a different network than the Splunk indexer, but they still resolve in DNS. Old server was running CentOS, new server is running Ubuntu 18.04. All other hosts that I index run Splunk universal forwarder, and when those logs make it to my indexer, they are already coming in with hostnames and not IPs.

The traffic is coming on typical udp/514, one from a cisco ASA, the other from a Cisco Switch. Prior to moving the Splunk instance, hostnames resolved fine. The DNS server is the same as it was before.

They resolve fine with nslookup:

[root@splunk ~]$ nslookup       name = Switch.

Authoritative answers can be found from:

[root@splunk ~]$ nslookup      name = CiscoASA.

Authoritative answers can be found from:

alt text

Any idea why these wouldn't resolve with Splunk indexer?

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...