1) Install IA-infoblox-atc app (https://splunkbase.splunk.com/app/3860)
- To create a new modular input configuration click
Create New Modular Input.
- Modular Input Name: Name for the modular input configuration.
- Hostname: The URL provided for the Infoblox instance without the https:// portion of the address. For production usage: csp.infoblox.com
- Interval: The number of seconds between data collections. 60 second is recommended. Tests with 15 seconds seems fine and accelerate the acquisition of past events
- Token: The API token generated by Infoblox for the instance. Available on csp.infoblox.com under username > user preferences > API Key > Show
- t0: t0 is start time for the first poll - unix timestamp (Note that after the first poll the value is stored in the modular input checkpoint)
- t1: t1 is end time for the first poll - unix timestamp (max delta is 24h)
- Use Proxy: Will a proxy server be used.
- Proxy Name: Name of the stanza configured in the proxy configuration.
2) Install infoblox-atc app (https://splunkbase.splunk.com/app/3850)
3) Customize external lookup to use your personal Dossier keys (optional)
l200 var username= * Dossier key - optional. Available on https://platform.activetrust.net under username > User Settings > Manage API Keys > Edit >
4) Bump to force the atc_security.js refresh http://your-splunk-host:8000/en-US/_bump
Note that on upgrade, step 3 and 4 must be done again
If you have duplicated results of top over 100%
edit the props.conf and add the following line:
To reset T0 and T1, you have to reset checkpoint using the command:
splunk clean inputdata infoblox
Fix props.conf KV_MODE=none issue
Added support for Categories filtering and multiple modular input filtering
Added Event acquisition troubleshoot dashboard
Removed dependency to rest_ta
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.