Splunk Enterprise Security

Infoblox CIM unknown fields

Path Finder

Hi there,

In order to make certain dashboards fill up in Enterprise Security we need to have dns.message_type show up yet for all events these are marked as "unknown". What's going wrong? The events do have "query" or "response" in them and the field extractions are working fine.

Kind regards,

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!