Is there a way to enable DNS caching in Splunk in order to not overwhelm a DNS server with repetitive lookups?
There is no way to do this in Splunk. The only way I've found is to use an external BIND based DNS cacheing solution and have all of the Splunk CORE infrastructure leverage that.
Link to How-To:
http://www.tecmint.com/install-configure-cache-only-dns-server-in-rhel-centos-7/
There is no way to do this in Splunk. The only way I've found is to use an external BIND based DNS cacheing solution and have all of the Splunk CORE infrastructure leverage that.
Link to How-To:
http://www.tecmint.com/install-configure-cache-only-dns-server-in-rhel-centos-7/