- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Using Splunk Stream Aggregation with Network Resolution Data Model
att35
Builder
01-07-2021
01:36 PM
Hi,
We are using Splunk Stream to get DNS logs into Splunk and it maps seamlessly with the Network Resolution Data model as well. To get cleaner data, I created another DNs stream but this time with some aggregation as shown below. Intent is to get concise summaries of DNS events without overwhelming the Indexers.
Now instead of field "query", data is coming as field values(query) which no longer maps to Network Resolution Data Model. DNS.query now reads unknown.
Has anyone come across this issue? Would renaming the field resolve the issue or is there a better way to fix the mapping?
Thanks,
~ Abhi
