Quantcast
Channel: Questions in topic: "datamodel"
Viewing all articles
Browse latest Browse all 226

Splunk App for Enterprise Security: Network Resolution (DNS) datamodel not populating

$
0
0
The dns datamodel is not populating because out of the box neither ES or the Windows Infrastructure app have the tag constraints defined. The datamodel is looking for the following three tags "tag=network tag=dns tag=resolution" for windows debug dns requests these tags are not defined anywhere. Is there another app that is required to create these tags? or are there eventtypes that exist that can be mapped for example to the resolution tag?

Viewing all articles
Browse latest Browse all 226

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>