Download and configure the Splunk Add-on for Windows DNS
The Splunk Add-on for Windows DNS collects DNS data and is available on Splunkbase. When you install the add-on into universal forwarders on your DNS servers, the add-on collects DNS data and sends it to the indexer.
Note: If you are using TA-Windows version 6.0.0 version or later then you do not need TA_AD and TA_DNS, as they are merged with TA-Windows. To configure TA-Windows v6.0.0, Please refer to Deploy and configure the Splunk Add-on for Windows v6.0.0 or later.
More information about the DNS add-on
The following table lists details about the Splunk Add-on for Windows DNS.
Add-on | Description |
---|---|
Splunk_TA_Microsoft_DNS | For DNS Servers that run Windows Server 2008/2008 R2 and later |
Download the Splunk Add-on for Windows DNS
Like the Splunk Add-on for Microsoft Active Directory, the Splunk Add-on for Windows DNS is available on Splunkbase. Make sure you download the latest version of the app. You might need to sign in with your Splunk account before the download starts.
- In a web browser, proceed to the Splunk Add-on for Windows DNS download page.
- Click the download link to begin the download process.
- When prompted, choose an accessible location on your deployment server to save the download. Do not attempt to run the download.
- Use an archive utility such as WinZip to unarchive the file to an accessible location.
Configure the Splunk Add-ons for Windows DNS
The Splunk Add-on for Windows DNS does not require configuration by default. When you install it onto DNS servers, it immediately begins collecting data as long as you have configured DNS debug logging.
Next Step
You have downloaded the Splunk App for Microsoft Exchange and can now access the Splunk Add-ons for Window DNS. The next step involves deploying those add-ons into the deployment clients that you install on your Active Directory DNS servers.
Configure Windows Domain Name Server | Deploy the Splunk Add-on for Windows DNS |
This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 4.0.0, 4.0.1, 4.0.2, 4.0.3
Feedback submitted, thanks!