Splunk Enterprise Security

Infoblox Sourcetype Branch Failures

panovattack
Communicator

We are taking in infoblox logs via syslog and are getting inconsistent results. We have a clustered environment. The infoblox app is installed on a search head and the infoblox data is coming in via syslog on an indexer. On the indexer, the sourcetype is manually set to infoblox:file. The last several days, the branch to infoblox:dhcp and infoblox:dns worked perfectly. Over the last couple days we are now only seeing infoblox:file, as if the sourcetype branches are no longer working. On the search head, we've verified the sourcetypes and the transforms. I can't seem to figure out why this is occurring. Do we need to install the infblox app on the indexer as well? This breaks Splunk Common Information Model (CIM) compliance and by extension Splunk Enterprise Security. Any advice on troubleshooting?

Splunk Add-on for Infoblox Splunk_TA_infoblox 1.0.2

0 Karma
1 Solution

panovattack
Communicator

Resolved by pushing application to indexer.

View solution in original post

0 Karma

panovattack
Communicator

Resolved by pushing application to indexer.

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

Which Infoblox add-on are you using? The TA-infoblox or the Splunk Add-on for Infoblox? I just want to make sure your post is tagged correctly.

0 Karma

panovattack
Communicator

Good catch. Fixed.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...