I'm using the Splunk_TA_infoblox add-on in two ways:
The TA was originally deployed without the part 1 above. That worked fine. But now with part 1 deployed, part 2 seems to have stopped working.
When search for "index=ipam_secure sourcetype=infoblox:dns", for example, I get events back but no field extractions.
Since the [infoblox:dns] stanza is unchanged on the search heads, I am puzzled as why the props and transforms stopped working. Any pointers would be much appreciated!