Infoblox DDI is a popular DNS, DHCP and IPAM (DDI) system. OOTB there are integrations (via add-ons) with Splunk which provide information about DHCP and DNS services, but there are no IPAM data flows. Luckily, Infoblox (actual product name is NIOS) provides a good REST API that can be used to overcome this gap.
This custom technical add-on for Infoblox APIs was built using the Splunk Add-on Builder app (https://splunkbase.splunk.com/app/2962/). The add-on should be installed on your Heavy Forwarders/Indexers and your Search Head instances.
There are three main inputs that can be configured in the TA on your Heavy Forwarder/Indexer:
- /record:host - this lists all host records (from DNS)
- /record:host_ipv4addr - this lists all IPv4 addresses
- /network - this lists all network segments available in IPAM + extended attributes (e.g. location)
REST API URL is usually found at: https://<your_infoblox_instance>:443/wapi/v2.7
For authentication the add-on uses Basic Auth mechanism. Read the API docs here: https://docs.infoblox.com/download/attachments/8945695/Infoblox_RESTful_API_Documentation_2.9.pdf for further details.
|REST API home||https://<your_infoblox_instance>:443/wapi/v2.7|
|HTTP request timeout||180|
The TA logs are sent into the "_internal" index by default. You should perform a search like the following:
This search will return the contents of the TA logs for the time range you select.
Note that if you see some errors mentioning "next page id" this will be normal, because this means that the input has reached the end of the list of items returned by the API. Anything else deserves to be investigated.
Updated permissions in package to follow best-practices.
Updated icon set and colors. Everything else is the same.
Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.