I'm not seeing the Network Resolution/DNS datamodel/dataset populated from the Splunk Add-on for Microsoft Windows DNS. The add-on was installed per the documentation on all Windows DNS servers.
Couple notes:
Thank you.
Ed
Unfortunately this Add-on doesn't match the CIM for Network Resolution DNS.
It's really strange that Splunk wouldn't make all the extractions and calculations match sowe could accelerate this data and use it with Splunk ES or Splunk Security Essentials.
You can try creating aliases and tagging the events to match the CIM Data model, but I think it should have been done out of the box by Splunk.
Unfortunately this Add-on doesn't match the CIM for Network Resolution DNS.
It's really strange that Splunk wouldn't make all the extractions and calculations match sowe could accelerate this data and use it with Splunk ES or Splunk Security Essentials.
You can try creating aliases and tagging the events to match the CIM Data model, but I think it should have been done out of the box by Splunk.
This is actually not very easy to do with the default Windows DNS logging. Firstly, to populate the Network Resolution, one would need to correlate request and response records. But beyond that, Microsoft logs DNS at a debug level and logs are multiple lines long and very difficult to parse.
Splunk does do the aggregation and parsing in the Stream app, but even that does not handle the datamodel mapping. A shame really, because it is not really clear how the Network Resolution model is supposed to be used with a number of DNS return types.