Lookups for the Splunk Add-on for ISC BIND
The Splunk Add-on for ISC BIND has four lookup files. The lookup files map fields from ISC BIND to CIM-compliant values in the Splunk platform. The lookup files are located in
$SPLUNK_HOME/etc/apps/Splunk_TA_isc-bind/lookups
.
Filename | Description |
---|---|
isc_bind_severities.csv
|
Maps vendor_severity to severity .
|
isc_bind_category.csv
|
Maps sourcetype to vendor_category .
|
isc_bind_action.csv
|
Maps vendor_action to action .
|
isc_bind_reply_code.csv
|
Maps response_code to reply_code and reply_code_id .
|
Troubleshoot the Splunk Add-on for ISC BIND |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!