Reply
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Is there a way for me to identify the difference between isc:bind:query logs and infoblox:dns?
Options
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-06-2024 10:13 AM
647     0
I am trying to route the logs into Cribl to be forwarder on to Splunk. I was hoping there was a flag in the log that I can use to differentiate from the two different logs. I assume there has to be, right ?
Re: Is there a way for me to identify the difference between isc:bind:query logs and infoblox:dns?
Options
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-06-2024 11:23 AM
647     0
Just for a little more clear: is there a flag in the syslog from Infoblox that will allow me to sort the events into two different sourcetypes: isc:bind:query logs and infoblox:dns