10-04-2016 05:39 AM - edited 10-04-2016 05:45 AM
I'm new to reporting, how do I find hosts who queried a specific domain name?
10-04-2016 06:02 AM - edited 10-04-2016 06:03 AM
If reporting feature was configured properly, you can check this information at the "DNS Domain Queried by Client" dashboard.
From the admin guide: The DNS Domain Queried by Client dashboard shows the DNS domains being queried by the client. This dashboard displays the DNS domains that are being queried from both the internal and external sources.
Hope this helps!
10-04-2016 06:10 AM
Where do I find DNS Domain Queried by Client dashboard? We have the integrated splunk reporting appliance.
Or can I build a query myself? Ifso, how?
Thx for the reply.
10-04-2016 06:51 AM
If you're using NIOS 7.3+: Navigate to "Reporting" tab, then to 'Dashboards" and check the list for the item.
From what I've seen, this dashboard is only available to NIOS versions above 7.3.x
If you're using NIOS in different versions I think the "DNS Top Clients Per Domain" report ("Reporting" tab, then "Reports") might be useful in this case.
If you are looking for real-time logging for this query, you can enable the query logging on the Infoblox member and look for the query inside the member's syslog.
Hope it helps!
10-04-2016 11:13 AM
The "DNS Domain Queried by Client" report requires the Data Collector VM. The Data Collector is a free VM (currently in beta) which is designed to offload the processing of DNS log data from the grid members. It is currently in beta, but fully functional. You should reach out to your Infoblox rep and request to participate in the beta program.