The short of it is that we gave up on the parsing and decided to leverage "Splunk Stream" for DNS. We have had zero issues with the approach to date and have gotten the data we are looking for in terms of the query itself as well as the resulting response. The fields you want to collect are configurable which means less data to ingest into Splunk (vs the parsing/filtering that had to be done at search time). Happy to discuss further, so let me know.
... View more