Splunk Enterprise Security

Does Network resolution datamodel includes outbound and inbound DNS transfers?

Woodpecker
Path Finder

Does the network resolution datamodel includes both Outbound and Inbound DNS transfers?

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

The datamodel includes query_type field so depending on your source, its configuration and the add-on you're using for data ingestion, I suppose it might include AXFR or IXFR. But I'd test before relying on it.

0 Karma
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...