Splunk Enterprise Security

Why are TA-DNSServer-NT6 fields, lookups, and aliases not showing in the Splunk App for Enterprise Security?

jsmith39
Path Finder

Most, but not all of the field extractions, lookups, and aliases created in the TA-DNSServer-NT6 app are viewable when looking through the Search and Reporting application, but not when searching through the Enterprise Security application.

The TA-DNSServer-NT6 sharing is set to Global (everyone-read,admin-write)

Unsure why only a handful of Lookups generated fields are viewable through ES, but everything is viewable through Search&Reporting.

0 Karma

jsmith39
Path Finder

I'm guessing this is some kind of bug with how Enterprise Security ingests applications, if I copy the props and transforms from TA-DNSServer-NT6/local and place them in SplunkEnterpriseSecuritySuite/local then I get all the field extractions, etc that I'm expecting.

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...