We are using Splunk Stream to get DNS logs into Splunk and it maps seamlessly with the Network Resolution Data model as well. To get cleaner data, I created another DNs stream but this time with some aggregation as shown below. Intent is to get concise summaries of DNS events without overwhelming the Indexers.
Now instead of field "query", data is coming as field values(query) which no longer maps to Network Resolution Data Model. DNS.query now reads unknown.
Has anyone come across this issue? Would renaming the field resolve the issue or is there a better way to fix the mapping?