Splunk Enterprise Security

How to Monitor Multiple DNS requests which are not resolved by DNS server from a particular source using SPL

dhananjay
Loves-to-Learn Lots

Conditons to create query:

1) Query should not contain any eventcode

2) Query must be build from DNS data model

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

This is a bit vague - what events do you have (please share some examples)? how often do you want to check? over what time period? which source are you interested in? are you looking for differences in resolutions or just the number of requests resolved?

0 Karma

dhananjay
Loves-to-Learn Lots

I have corrected my previous question so please check it.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Thanks - hopefully someone will know what the DNS Data Model looks like and what events are available from it, but it is beyond my ken.

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...