Skip to main content
Warning
This app is archived. App archiving documentation
TA-pihole app icon

TA-pihole

#### ## TA-pihole ## v 1.0.0 ## 8/13/2018 ## Dan Potter ## @dpotter on slack #### This app was built for analyzing data from piHole and other dnsmasq based logs for DHCP/dns data. It is CIM compliant with the Network Resolution (DNS) data model. There was a focus on being able to filter the events to gain better insight to your network. Built by Brian Daniel Potter
splunk product badge

Default Version 1.0.0

August 13, 2018

Compatibility

Splunk Enterprise

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 4.x

Rating
5
(1)

Log in to rate this app

Support
Archived Add-on

#### ## TA-pihole ## v 1.0.0 ## 8/13/2018 ## Dan Potter ## @dpotter on slack #### This app was built for analyzing data from piHole and other dnsmasq based logs for DHCP/dns data. It is CIM compliant with the Network Resolution (DNS) data model. There was a focus on being able to filter the events to gain better insight to your network. No support is assumed or provided beyond this README. Please be sure to set the correct onboard sourcetype (pihole), or associate the appropriate log with the correct sourcetype from /default/props.conf **For the best visibility, please ensure you use log-queries=extra **In your dnsmasq.conf file or advanced configuration options. This ensures we have complete query/response data