Splunk Enterprise Security

How to Monitor Multiple DNS requests which are not resolved by DNS server from a particular source using SPL

dhananjay
Loves-to-Learn Lots

Conditons to create query:

1) Query should not contain any eventcode

2) Query must be build from DNS data model

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

This is a bit vague - what events do you have (please share some examples)? how often do you want to check? over what time period? which source are you interested in? are you looking for differences in resolutions or just the number of requests resolved?

0 Karma

dhananjay
Loves-to-Learn Lots

I have corrected my previous question so please check it.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Thanks - hopefully someone will know what the DNS Data Model looks like and what events are available from it, but it is beyond my ken.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...