Introduction
Splunk default fields
Splunk server adds the following default fields to each event in every index.
Field Name | Description | Values/Range | ||||||||
| Indicates the hour when an event occurred. To narrow your search for specific event timestamps, you can use the default datetime fields. Click here for more information on datetime fields. | Range: 0-23 | ||||||||
| Indicates the day of the month when the event occurred | Range: 1-31 | ||||||||
| Indicates the exact minute when the event occurred | Range: 0-59 | ||||||||
| Indicates the month during which an event occurred | |||||||||
| Indicates the second in which an event occurred | Range: 0-59 | ||||||||
| Indicates the day of the week in which an event occurred | Example: Sunday, Monday, etc. | ||||||||
| Indicates the year in which an event occurred | |||||||||
| Indicates the time for the local timezone of an event, expressed as hours in Unix Time | |||||||||
| Indicates events of the same type based on a given search. Click here for more information | Example: splunkd-log | ||||||||
| Contains information about the originating hostname or a network IP address that generates the event | Example: reporting-1.com | ||||||||
| Contains the name of the index with which a given event is indexed | Example: ib_dns_summary | ||||||||
| Contains information about the number of lines in an event before it is indexed | Example: 1 | ||||||||
| Contains information about the pattern of the first thirty punctuation characters in the first line of the event with which it is associated. It shows how an event looks when all letters, numbers, and spaces are removed and contains characters such as periods, colons, parentheses, quotes, question marks, dashes, and underscores. Click here for more information. |
| ||||||||
| Contains the name of the file, stream, or other input details from which the event originates | Example: si-search-dns-query-reply | ||||||||
| Specifies the format of data input from which the event originates | Stash | ||||||||
| Contains the name of the Splunk server that comprises the event | Example: reporting-2.com-2-slave | ||||||||
| Contains the name of the Splunk server group | String |
Anchor | ||||
---|---|---|---|---|
|
Field Name | Description | Values/Range | Source of Data | ||||||
| Specifies the extensible attribute | String | __grouping_by_ea_tag_lookup lookup from /storage/splunk/etc/apps/infoblox/lookups/grouping_by_ea_tag_map.csv with host value as input OR pool_ea_lookup_csv lookup from /storage/splunk/etc/apps/infoblox/lookups/idns_pools.csv with pool value as input OR resource_pool_ea_lookup_csv lookup from /storage/splunk/etc/apps/infoblox/lookups/idns_resources.csv with RESOURCE value as input OR network_ea_lookup_csv lookup from /storage/splunk/etc/apps/infoblox/lookups/network.csv with NETWORK value as input | ||||||
| Specifies the hardware type | Example: IB-4030 | nios_member_hw_lookup lookup from /storage/splunk/etc/apps/infoblox/lookups/nios_member_hw.csv with |
host |
value as input. | |||||||
| Specifies the maximum objects in the database for a host |
Example: 8000000. | nios_member_hw_lookup |
lookup from /storage/splunk/etc/ap. |
| Specifies the maximum number of DHCP leases per second for a host | Example: 15.0 |
nios_member_hw_lookup |
lookup from /storage/splunk/etc/apps/infoblox/lookups/nios_member_hw.csv with |
host |
value as input. | ||||||||
| Specifies the maximum DNS queries per second for a host | Example: 1000000.0 |
nios_member_hw_lookup |
lookup from /storage/splunk/etc/apps/infoblox/lookups/nios_member_hw.csv with |
host |
value as input. | ||||||||
| Specifies the IP address of the member | IP address |
nios_member_ip_lookup |
lookup from /storage/splunk/etc/apps/infoblox/lookups/nios_member_ip.csv with |
host |
value as input | |||||||||
| Specifies the byte at which the timestamp ends. These values are based on the TIME_FORMAT that is specified for a sourcetype under props.conf. | Example: 26 | |||||||
| Specifies the byte at which the timestamp starts | Example: 0 |
Indexes and Extracted Data
...
Most of the fields in this index are extracted directly from the audit.log file. Some of these those fields are listed below:
Extracted Field Name | Description of the field | Values/Range | Source of Data |
ACTION | Indicates the action taken | String. Example: Called | Infoblox audit logs |
ADMIN | Indicates the name of the admin | String. Example: root | Infoblox audit logs |
EA | Common Extracted fields | ||
EXEC_STATUS | Indicates the execution status | String. Example: Pending Approval | Infoblox audit logs |
HWTYPE | Common Extracted fields | ||
MAX_DB_OBJECTS | Common Extracted fields | ||
MAX_DHCP_LPS | Common Extracted fields | ||
MAX_DNS_QPS | Common Extracted fields | ||
MEMBER_IP | Common Extracted fields | ||
MESSAGE | Indicates the message | String. Example: to=Serial 040Console apparently_via=Direct auth=Local group=.admin-group | Infoblox audit logs |
OBJECT_NAME | Indicates the object name | String. Example: RequestRestartServiceStatus | Infoblox audit logs |
OBJECT_TYPE | Indicates the object type | String. Example: Shared AAAA Record | Infoblox audit logs |
TIMESTAMP | Indicates the timestamp | Timestamp. Example: 2017-01-31 01:57:05 | Infoblox audit logs |
action | Indicates the action | Example: update, insert | Infoblox audit logs |
address | Example: 10.0.0.0 | Infoblox audit logs | |
auth | Example: Local | Infoblox audit logs | |
cidr | Example: 8 | Infoblox audit logs | |
code | Example: created | Infoblox audit logs | |
comment | String | Infoblox audit logs | |
date_hour | Splunk Default field | ||
date_mday | Splunk Default field | ||
date_minute | Splunk Default field | ||
date_month | Splunk Default field | ||
date_second | Splunk Default field | ||
date_wday | Splunk Default field | ||
date_year | Splunk Default field | ||
date_zone | Splunk Default field | ||
eventtype | Splunk Default field | ||
group | Example: admin-group | Infoblox audit logs | |
host | Splunk Default field | ||
index | Splunk Default field | ||
linecount | Splunk Default field | ||
member | Example: Member:infoblox.localdomain | Infoblox audit logs | |
network_view | Example: default | Infoblox audit logs | |
punct | Splunk Default field | ||
source | Splunk Default field | ||
sourcetype | Splunk Default field | ||
splunk_server | Splunk Default field | ||
splunk_server_group | Splunk Default field | ||
user | Example: admin | Infoblox audit logs |
...
Extracted Field Name | Description of the field | Values/Range | Source of Data | ||||||
CLIENT | Indicates the DNS client | String | Infoblox DNS query | ||||||
| Indicates the count | Integer | Infoblox DNS query and DNS Record Scavenging | ||||||
EA | Common Extracted fields | ||||||||
FQDN | Indicates the FQDN | String | Infoblox DNS query | ||||||
HITS | Indicates the DNS cache hits count | Integer | Infoblox DNS query | ||||||
HNAME | Indicates the HNAME | String | Infoblox DNS query | ||||||
HWTYPE | Common Extracted fields | ||||||||
| Indicates the latency count | Integer | Infoblox DNS performance | ||||||
MAX_DB_OBJECTS | Common Extracted fields | ||||||||
MAX_DHCP_LPS | Common Extracted fields | ||||||||
MAX_DNS_QPS | Common Extracted fields | ||||||||
MEMBER | Specifies the member | String | DNS Record Scavenging | ||||||
MEMBER_IP | Common Extracted fields | ||||||||
MISSES | Specifies DNS cache miss count | Integer | Infoblox DNS query | ||||||
| Specifies query count | Integer | Infoblox DNS query | ||||||
REST | REST | String | Infoblox DDNS | ||||||
SOURCE | SOURCE | String | Infoblox DDNS | ||||||
SOURCEA | SOURCEA | IP address | Infoblox DDNS | ||||||
TLD | Specifies the top-level domain name | String | Infoblox DNS query | ||||||
TYPE | RR Type | String. Example: nxdomain | Infoblox DNS query and DNS Record Scavenging | ||||||
TYPEA | TYPEA | String. Example: Success | Infoblox DDNS | ||||||
VIEW | It refers Refers to the DNS view key to map DNS view through lookup. See display_name field. | String | Infoblox DNS query | ||||||
ZONE | Indicates the name of the zone | String | Infoblox DDNS | ||||||
date_hour | Splunk Default field | ||||||||
date_mday | Splunk Default field | ||||||||
date_minute | Splunk Default field | ||||||||
date_month | Splunk Default field | ||||||||
date_second | Splunk Default field | ||||||||
date_wday | Splunk Default field | ||||||||
date_year | Splunk Default field | ||||||||
date_zone | Splunk Default field | ||||||||
| Specifies the name of the DNS view | String | DNS view lookup from dns_viewkey_displayname.csv using the View field value. | ||||||
eventtype | Splunk Default field | ||||||||
failure | Specifies the DNS FAILURE query count | Integer | |||||||
host | Splunk Default field | ||||||||
index | Splunk Default field | ||||||||
linecount | Splunk Default field | ||||||||
nxdomain | Specifies the DNS NXDOMAIN query count | Integer | |||||||
nxrrset | Specifies the DNS NXRRSET query count | Integer | |||||||
other | Specifies the DNS other query count | Integer | |||||||
punct | Splunk Default field | ||||||||
referral | Specifies the DNS REFERRAL query count | Integer | |||||||
source | Splunk Default field | ||||||||
sourcetype | Splunk Default field | ||||||||
splunk_server | Splunk Default field | ||||||||
splunk_server_group | Splunk Default field | ||||||||
success | Specifies the DNS success query count | ||||||||
timeendpos | Common extracted fields | ||||||||
timestartpos | Common extracted fields |
...
Extracted Field Name | Description of the field | Values/Range | Source of Data |
EA | Common Extracted fields | ||
HWTYPE | Common Extracted fields | ||
MAX_DB_OBJECTS | Common Extracted fields | ||
MAX_DHCP_LPS | Common Extracted fields | ||
MAX_DNS_QPS | Common Extracted fields | ||
MEMBER_IP | Common Extracted fields | ||
answer_count | Specifies the answer count | Integer | Infoblox DNS query capture |
date_hour | Splunk Default field | ||
date_mday | Splunk Default field | ||
date_minute | Splunk Default field | ||
date_month | Splunk Default field | ||
date_second | Splunk Default field | ||
date_wday | Splunk Default field | ||
date_year | Splunk Default field | ||
date_zone | Splunk Default field | ||
display_name | Specifies the DNS view | String | DNS View Lookup from dns_viewkey_displayname.csv using View field value. |
eventtype | Splunk Default field | ||
flag_aa | Flag AA | Boolean. Example: Y | Infoblox DNS query capture |
flag_ad | Flag AD | Boolean. Example: Y | Infoblox DNS query capture |
flag_edns | Flag EDNS | Boolean. Example: Y | Infoblox DNS query capture |
flag_recursion | Flag Recursion | Boolean. Example: Y | Infoblox DNS query capture |
host | Splunk Default field | ||
host_class | Specifies the host class | Example: IN | Infoblox DNS query capture |
host_type | Specifies the host type | Example: PTR | Infoblox DNS query capture |
index | Splunk Default field | ||
linecount | Splunk Default field | ||
message_type | Specifies the message type | Example: Query or Response | Infoblox DNS query capture |
name | Specifies the name | Host name. Example: 1.0.0.127.in-addr.arpa | Infoblox DNS query capture |
query | Specifies the query | Host name. Example: 213.31.102.10.in-addr.arpa | Infoblox DNS query capture |
query_class | Specifies the query class | Example: IN | Infoblox DNS query capture |
query_count | Specifies the query count | Integer. Example: 1 | Infoblox DNS query capture |
query_source | Specifies the query source | Example: I, E | Infoblox DNS query capture |
query_type | Specifies the DNS query type | Example: PTR | Infoblox DNS query capture |
rdata | RDATA | String. This value depends on the query type. | Infoblox DNS query capture |
reply_code | Specifies the reply code | String. Example: ServFail, NoError | Infoblox DNS query capture |
source | Splunk Default field | ||
sourcetype | Splunk Default field | ||
splunk_server | Splunk Default field | ||
splunk_server_group | Splunk Default field | ||
src_ip | Specifies the source IP | IP Address | Infoblox DNS query capture |
src_port | Specifies the source port | Integer | Infoblox DNS query capture |
time_msec | Specifies time in milliseconds | Integer | Infoblox DNS query capture |
timeendpos | Common extracted fields | ||
timestamp | Indicates the timestamp | Integer | Infoblox DNS query capture |
timestartpos | Common Extracted fields | ||
transport | Specifies the mode of transport | Example: UDP, TCP | Infoblox DNS query capture |
ttl | Specifies the TTL | Integer. Example: 3600 | Infoblox DNS query capture |
view | Specifies the view | Example: 1, 2 | Infoblox DNS query capture |
...
Extracted Field Name | Description of the field | Values/Range | Source of Data | ||||||
EA | Common Extracted fields | ||||||||
HWTYPE | Common Extracted fields | ||||||||
MAX_DB_OBJECTS | Common Extracted fields | ||||||||
MAX_DHCP_LPS | Common Extracted fields | ||||||||
MAX_DNS_QPS | Common Extracted fields | ||||||||
MEMBER_IP | Common Extracted fields | ||||||||
NETWORK | Specifies the network address | Example: 10.0.0.0/8 | Evaluated from the address and cidr field values | ||||||
address | Specifies the DHCP client address | IP address | Infoblox DHCP performance | ||||||
address_total | Specifies the total number of addresses | Integer | Infoblox DHCP performance | ||||||
cidr | Specifies the CIDR | Example: 24 | Infoblox DHCP performance | ||||||
date_hour | Splunk Default field | ||||||||
date_mday | Splunk Default field | ||||||||
date_minute | Splunk Default field | ||||||||
date_month | Splunk Default field | ||||||||
date_second | Splunk Default field | ||||||||
date_wday | Splunk Default field | ||||||||
date_year | Splunk Default field | ||||||||
date_zone | Splunk Default field | ||||||||
dhcp_hosts | Specifies the DHCP hosts count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCP utilization | Integer | Infoblox DHCP performance | ||||||
dhcp_utilization_status | Specifies the DHCP utilization status | String | Infoblox DHCP performance | ||||||
dhcpv4ack | Specifies the DHCPv4 ACK message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv4 decline message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv4 discover message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv4 inform message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv4 lease active message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv4 lease query message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv4 lease unassigned message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv4 lease unknown message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv4 NAK message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv4 offer message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv4 release message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv4 request message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 advertise message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 confirm message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 decline message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 information request message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 lease query message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 lease query reply message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 rebind message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 reconfigure message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 relay forward message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 relay reply message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 release message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 renew message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 reply message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 request message count | Integer | Infoblox DHCP performance | ||||||
| Specifies the DHCPv6 solicit message count | Integer | Infoblox DHCP performance | ||||||
display_name | Specifies the DNS View | String | DNS View Lookup from dns_viewkey_displayname.csv using the View field value | ||||||
| Specifies the dynamic hosts count | Integer | Infoblox DHCP performance | ||||||
end_address | Specifies the end IP address | IP address | Infoblox DHCP performance | ||||||
eventtype | Splunk Default field | ||||||||
host | Splunk Default field | ||||||||
index | Splunk Default field | ||||||||
linecount | Splunk Default field | ||||||||
members | Specifies the DHCP member | Example: infoblox.localdomain | Infoblox DHCP performance | ||||||
ms_servers | Specifies the MS servers | IP address | Infoblox DHCP performance | ||||||
protocol | Specifies the DHCP protocol | Example: IPV4 | |||||||
punct | Splunk Default field | ||||||||
ranges | Specifies the DHCP ranges count | Integer | Infoblox DHCP performance | ||||||
source | Splunk Default field | ||||||||
sourcetype | Splunk Default field | ||||||||
splunk_server | Splunk Default field | ||||||||
splunk_server_group | Splunk Default field | ||||||||
start_address | Specifies the start IP address | IP address | Infoblox DHCP performance | ||||||
| Specifies the static hosts count | Integer | Infoblox DHCP performance | ||||||
timeendpos | Common extracted fields | ||||||||
timestamp | Specifies the timestamp of the event | Example: 2017-02-04 03:45:53 | Infoblox DHCP performance | ||||||
timestartpos | Common extracted fields | ||||||||
View | Specifies the network view | Example: default | Infoblox DHCP performance |
...
Extracted Field Name | Description of the field | Values/Range | Source of Data |
ACTION | Specifies the action | String. Example: Issued | Infoblox DHCP lease history |
CIDR | Specifies the CIDR | Integer | Infoblox DHCP lease history |
DEVICE_CLASS | Specifies the device class | String. Example: Linux | fingerprint_device_class_lookup lookup from |
EA | Common Extracted fields | ||
END_EPOCH | Specifies the end epoch time | Integer | Infoblox DHCP lease history |
FP | Specifies the name of the DHCP fingerprint | String. Example: No Match | Infoblox DHCP lease history |
FP_CIDR | Specifies the fingerprint CIDR | Integer. Example: 8 | Infoblox DHCP lease history |
FP_NW | Specifies the fingerprint network | Network address. Example: 10.0.0.0 | Infoblox DHCP lease history |
FP_RANGE | Specifies the fingerprint range | Network range. Example: 10.0.0.1-10.0.0.200 | Infoblox DHCP lease history |
FP_VIEW | Specifies the fingerprint view | String. Example: default | Infoblox DHCP lease history |
HWTYPE | Common Extracted fields | ||
LEASE_IP | Specifies the lease IP address | IP address | Infoblox DHCP lease history |
MAC_DUID | Specifies the MAC address | MAC address | Infoblox DHCP lease history |
MAX_DB_OBJECTS | Common Extracted fields | ||
MAX_DHCP_LPS | Common Extracted fields | ||
MAX_DNS_QPS | Common Extracted fields | ||
MEMBER_IP | Common Extracted fields | ||
MS Server | Specifies the MS server | IP Address | Infoblox DHCP lease history |
NW | Specifies the network | Network address. Example: 10.0.0.0 | Infoblox DHCP lease history |
OPTION12HOST | Specifies the host name that is sent using DHCP Option 12 | String. Example: Fedora21 | Infoblox DHCP lease history |
OS_NUMBER | Specifies the OS number | Integer | Infoblox DHCP lease history |
PROTO | Specifies the protocol | String. Example: dhcpd | Infoblox DHCP lease history |
SFP | SFP | String. Example: Ubuntu/Debian 5/Knoppix 6 | Infoblox DHCP fingerprint |
START_EPOCH | Specifies the start epoch time | Integer | Infoblox DHCP lease history |
VIEW | Specifies the view | Infoblox DHCP lease history | |
date_hour | Splunk Default field | ||
date_mday | Splunk Default field | ||
date_minute | Splunk Default field | ||
date_month | Splunk Default field | ||
date_second | Splunk Default field | ||
date_wday | Splunk Default field | ||
date_year | Splunk Default field | ||
date_zone | Splunk Default field | ||
display_name | Specifies the DNS view | String | DNS View Lookup from dns_viewkey_displayname.csv using the View field value. |
eventtype | Splunk Default field | ||
host | Splunk Default field | ||
index | Splunk Default field | ||
linecount | Splunk Default field | ||
punct | Splunk Default field | ||
source | Splunk Default field | ||
sourcetype | Splunk Default field | ||
splunk_server | Splunk Default field | ||
splunk_server_group | Splunk Default field | ||
timeendpos | Common extracted fields | ||
timestartpos | Common extracted fields |
...
Extracted Field Name | Description of the field | Reports | Values/Range | Source of Data | Remarks |
CLIENT | Specifies the IP address of the DNS client | Example: 10.39.18.60 | |||
COUNT | Specifies the count of DNS queries | si_dns_top_clients | Integer | ||
Specifies the count of SERVFAIL errors that are received for DNS clients | si_top_servfail_received_queries | Integer | |||
Specifies the count of NXDOMAIN/NOERROR replies for DNS clients | si_top_nxdomain_query | Integer | |||
Specifies the count of DNS domain name requests | si_dns_requested_domain | Integer | |||
Specifies the count of DNS queries per second | si_dns_qps_trend | Integer | |||
Specifies the count of DNS SERVFAIL errors that are sent for DNS queries | si_top_servfail_sent_queries | Integer | |||
Specifies the count of DNS timed-out recursive queries | si_top_timeout_queries | Integer | |||
Specifies the average count of DNS RPX hits | si_dns_rpz_hits | Integer | |||
Specifies the count of DNS clients per domain | si_top_clients_per_domain | Integer | |||
EA | Common Extracted fields | ||||
FQDN | Specifies the fully qualified domain name | si_dns_requested_domain and si_top_clients_per_domain | Example: 213.31.102.10.in-addr.arpa | ||
HWTYPE | Common Extracted fields | ||||
MAX_DB_OBJECTS | Common Extracted fields | ||||
MAX_DHCP_LPS | Common Extracted fields | ||||
MAX_DNS_QPS | Common Extracted fields | ||||
MEMBER | Specifies the member | String | Infoblox DNS Summary | ||
MEMBER_IP | Common Extracted fields | ||||
TLD | Specifies top level domain names | si_dns_requested_domain | Example: arpa | ||
TYPE | Specifies the DNS response type | si_dns_query_reply, si_dns_qps_trend, and si_ddns_update | SUCCESS/NOERROR or REFERRAL or NXRRSET or NXDOMAIN or REFUSED or OTHER | ||
VIEW | It refers to the DNS view key to map DNS view through lookup. See display_name field. | si_dns_requested_domain, si_dns_member_qps_trend_per_hour, | Example: _default | ||
date_hour | Splunk Default field | ||||
date_mday | Splunk Default field | ||||
date_minute | Splunk Default field | ||||
date_month | Splunk Default field | ||||
date_second | Splunk Default field | ||||
date_wday | Splunk Default field | ||||
date_year | Splunk Default field | ||||
date_zone | Splunk Default field | ||||
display_name | Specifies the DNS view | si_dns_requested_domain, si_dns_top_clients, si_dns_member_qps_trend_per_hour, si_dns_member_qps_trend_per_day, si_dns_member_qps_trend, si_dns_qps_trend, si_ddns_update, si_dns_cache_hit_ratio, si_dns_rpz_hits, si_top_clients_per_domain, si_top_timeout_queries, si_top_servfail_sent_queries, si_top_nxdomain_query, and si_top_servfail_received_queries | Example: default.MS-2016 | Lookup from dns_viewkey_displayname.csv | |
eventtype | Splunk Default field | ||||
host | Splunk Default field | ||||
index | Splunk Default field | ||||
info_max_time | Common summary index fields | ||||
info_min_time | Common summary index fields | ||||
info_search_time | Common summary index fields | ||||
linecount | Splunk Default field | ||||
orig_host | Specifies the host name of the data source | Example: infoblox.com | Splunk added default field | ||
psrsvd_ct_COUNT | Here, ct = count. Contains the count information for the COUNT field. | si_dns_query_reply and si_dns_qps_trend | Splunk added special field | ||
psrsvd_ct_LATENCY | Contains the count information for the LATENCY field | si_dns_response_latency_trend | Splunk added special field | ||
psrsvd_ct_QCOUNT | Contains the count information for the QCOUNT field | si_dns_member_qps_trend_per_hour, | Splunk added special field | ||
psrsvd_gc | Here, gc = group count. It indicates the count for stats grouping and it is not scoped to a single field. | si_dns_query_reply, | Splunk added special field | ||
psrsvd_nc_COUNT | Here, nc = numerical count. It indicates the number of numerical values and contains the numerical count information for the COUNTfield. | si_dns_query_reply and si_dns_qps_trend | Splunk added special field | ||
psrsvd_nc_LATENCY | Contains the numerical count information for the LATENCY field | si_dns_response_latency_trend | Splunk added special field | ||
psrsvd_nc_QCOUNT | Contains the numerical count information for the QCOUNT field | si_dns_member_qps_trend_per_hour, | Splunk added special field | ||
psrsvd_nx_QCOUNT | Here, nx = maximum numerical value. It contains the maximum numerical value information for the QCOUNT field. | si_dns_member_qps_trend_per_hour , and | Splunk added special field | ||
psrsvd_sm_COUNT | Here, sm = sum. Contains the sum information for the COUNTfield. | si_dns_query_reply and si_dns_qps_trend | Splunk added special field | ||
psrsvd_sm_LATENCY | Contains the sum information for the LATENCY field. | si_dns_response_latency_trend | Splunk added special field | ||
psrsvd_sm_QCOUNT | Contains the sum information for the QCOUNT field | si_dns_member_qps_trend_per_hour, | Splunk added special field | ||
psrsvd_sx_QCOUNT | Here, sx = maximum lexicographical value. Contains the maximum lexicographical value information for the QCOUNT field | si_dns_member_qps_trend_per_hour , and si_dns_member_qps_trend_per_day | Splunk added special field | ||
psrsvd_v | Here, v = version. This is not scoped to a single field. | si_dns_query_reply, | Splunk added special field | ||
psrsvd_vt_COUNT | Here, vt = value type. It contains precision of the associated field. This field contains precision of the COUNTfield. | si_dns_query_reply and si_dns_qps_trend | Splunk added special field | ||
psrsvd_vt_LATENCY | Contains precision of the LATENCY field | si_dns_response_latency_trend | Splunk added special field | ||
psrsvd_vt_QCOUNT | Contains precision of the QCOUNT field | si_dns_member_qps_trend_per_hour, | Splunk added special field | ||
report | Contains the name of the report that populates the summary index | ||||
DNS Scavenge Object Count Trend data | si_dns_reclaimed_object_count_trend | ||||
DNS Top Clients report data | si_dns_top_clients | ||||
DNS Replies Trend data | si_dns_query_reply | ||||
DNS Top SERVFAIL Errors Received Report data | si_top_servfail_received_queries | ||||
DNS Response Latency Trend data | si_dns_response_latency_trend | ||||
DNS Daily Peak Hour Query Rate by Member Report data | si_dns_member_qps_trend_per_hour | ||||
DNS Top NXDOMAIN / NOERROR (no data) Report data | si_top_nxdomain_query | ||||
DNS Daily Query Rate by Member Report data | si_dns_member_qps_trend_per_day | ||||
DNS Query Rate by Member Report data | si_dns_member_qps_trend | ||||
DNS Top Requested Domain Names Report data | si_dns_requested_domain | ||||
DNS Queries Per Second Trend data | si_dns_qps_trend | ||||
DNS Top SERVFAIL Errors Sent Report data | si_top_servfail_sent_queries | ||||
DDNS Update Rate Trend data | si_ddns_update | ||||
DNS Cache Hit Rate Trend data | si_dns_cache_hit_ratio | ||||
DNS Top Timed-Out Recursive Queries Report data | si_top_timeout_queries | ||||
DNS RPZ Hits Reports data | si_dns_rpz_hits | ||||
DNS Top Clients per Domain Report data | si_top_clients_per_domain | ||||
search_name | Common summary index fields | ||||
search_now | Common summary index fields | ||||
source | Splunk Default field | ||||
sourcetype | Splunk Default field | ||||
splunk_server | Splunk Default field | ||||
splunk_server_group | Splunk Default field | ||||
timeendpos | Common extracted fields | ||||
timestartpos | Common extracted fields |
...
Extracted Field Name | Description of the field | Reports | Values/Range | Source of Data | Remarks |
ACTION | Specifies the action | String. Example: Issued | Infoblox DHCP summary | ||
DEVICE_CLASS | Specifies the device class | String. Example: Linux | fingerprint_device_class_lookup lookup from | ||
DHCP_RANGE | Specifies the DHCP range | Network range. Example: 10.0.0.1-10.0.0.200 | Evaluated from the start_address | ||
EA | Common Extracted fields | ||||
FP | Specifies the fingerprint data | String. Example: No Match | Infoblox DHCP summary | ||
HWTYPE | Common Extracted fields | ||||
LEASED_IP | Specifies the lease IP address | IP address | Infoblox DHCP summary | ||
MAC_DUID | Specifies the MAC address | MAC address | Infoblox DHCP summary | ||
MAX_DB_OBJECTS | Common Extracted fields | ||||
MAX_DHCP_LPS | Common Extracted fields | ||||
MAX_DNS_QPS | Common Extracted fields | ||||
MEMBER_IP | Common Extracted fields | ||||
Protocol | Specifies the DHCP protocol | String. Example: IPV4 | Infoblox DHCP summary | ||
SFP | Specifies the SFP | String. Example: Ubuntu/Debian 5/Knoppix 6 | os_number_fingerprint_lookup lookup from | ||
VIEW | It refers Refers to the DNS view key that is necessary to map the DNS view through lookup. See display_name field. | String | |||
date_hour | Splunk Default field | ||||
date_mday | Splunk Default field | ||||
date_minute | Splunk Default field | ||||
date_month | Splunk Default field | ||||
date_second | Splunk Default field | ||||
date_wday | Splunk Default field | ||||
date_year | Splunk Default field | ||||
date_zone | Splunk Default field | ||||
dhcp_utilization_status | Specifies the DHCP utilization status | String | Infoblox DHCP summary | ||
display_name | Specifies the DNS view | String | DNS View Lookup from | ||
end_address | Specifies the end IP address | IP address | Infoblox DHCP summary | ||
eventtype | Splunk Default field | ||||
host | Splunk Default field | ||||
index | Splunk Default field | ||||
info_max_time | Common summary index fields | ||||
info_min_time | Common summary index fields | ||||
info_search_time | Common summary index fields | ||||
linecount | Splunk Default field | ||||
members | Specifies the DHCP member | String. Example: infoblox.localdomain | Infoblox DHCP summary | ||
ms_servers | Specifies the MS servers | IP address | Infoblox DHCP summary | ||
orig_host | Specifies the host name of the data source | Example: infoblox.com | Splunk added default field | ||
psrsvd_ct_FREE_ADDRESSES | Specifies the count information for FREE_ADDRESSES field | si_dhcp_usage_trend | Splunk added special field | ||
psrsvd_ct_dhcp_utilization | Specifies the count for dhcp_utilization field | si_dhcp_range_utilization_trend | Splunk added special field | ||
psrsvd_ct_dynamic_hosts | Specifies the count for dynamic_hosts field | si_dhcp_usage_trend | Splunk added special field | ||
psrsvd_ct_static_hosts | Specifies the count for static_hosts field | si_dhcp_usage_trend | Splunk added special field | ||
psrsvd_ct_v4ack | Specifies the count for v4ack field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v4decline | Specifies the count for v4decline field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v4discover | Specifies the count for v4discover field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v4inform | Specifies the count for v4inform field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v4leaseactive | Specifies the count for v4leaseactive field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v4leasequery | Specifies the count for v4leasequery field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v4leaseunassigned | Specifies the count for v4leaseunassigned field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v4leaseunknown | Specifies the count for v4leaseunknown field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v4nak | Specifies the count for v4nak field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v4offer | Specifies the count for v4offer field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v4release | Specifies the count for v4release field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v4request | Specifies the count for v4request field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6advertise | Specifies the count for v6advertise field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6confirm | Specifies the count for v6confirm field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6decline | Specifies the count for v6decline field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6information_request | Specifies the count for v6information_request field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6leasequery | Specifies the count for v6leasequery field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6leasequery_reply | Specifies the count for v6leasequery_reply field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6rebind | Specifies the count for v6rebind field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6reconfigure | Specifies the count for v6reconfigure field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6relay_forward | Specifies the count for v6relay_forward field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6relay_reply | Specifies the count for v6relay_reply field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6release | Specifies the count for v6release field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6renew | Specifies the count for v6renew field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6reply | Specifies the count for v6reply field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6request | Specifies the count for v6request field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_ct_v6solicit | Specifies the count for v6solicit field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_gc | Here, gc = group count. The count for stats grouping and not scoped to a single field. | si_dhcp_usage_trend, si_dhcp_top_lease_client, | Splunk added special field | ||
psrsvd_nc_FREE_ADDRESSES | Specifies the numerical count for FREE_ADDRESSES field | si_dhcp_usage_trend | Splunk added special field | ||
psrsvd_nc_dhcp_utilization | Specifies the numerical count for dhcp_utilization field | si_dhcp_range_utilization_trend | Splunk added special field | ||
psrsvd_nc_dynamic_hosts | Specifies the numerical count for dynamic_hosts field | si_dhcp_usage_trend | Splunk added special field | ||
psrsvd_nc_static_hosts | Specifies the numerical count for static_hosts field | si_dhcp_usage_trend | Splunk added special field | ||
psrsvd_nc_v4ack | Specifies the numerical count for v4ack field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v4decline | Specifies the numerical count for v4decline field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v4discover | Specifies the numerical count for v4discover field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v4inform | Specifies the numerical count for v4inform field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v4leaseactive | Specifies the numerical count for v4leaseactive field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v4leasequery | Specifies the numerical count for v4leasequery field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v4leaseunassigned | Specifies the numerical count for v4leaseunassigned field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v4leaseunknown | Specifies the numerical count for v4leaseunknown field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v4nak | Specifies the numerical count for v4nak field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v4offer | Specifies the numerical count for v4offer field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v4release | Specifies the numerical count for v4release field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v4request | Specifies the numerical count for v4request field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6advertise | Specifies the numerical count for v6advertise field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6confirm | Specifies the numerical count for v6confirm field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6decline | Specifies the numerical count for v6decline field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6information_request | Specifies the numerical count for v6information_request field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6leasequery | Specifies the numerical count for v6leasequery field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6leasequery_reply | Specifies the numerical count for ' v6leasequery_reply ' field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6rebind | Specifies the numerical count for v6rebind field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6reconfigure | Specifies the numerical count for ' v6reconfigure field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6relay_forward | Specifies the numerical count for v6relay_forward field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6relay_reply | Specifies the numerical count for v6relay_reply field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6release | Specifies the numerical count for v6release field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6renew | Specifies the numerical count for v6renew field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6reply | Specifies the numerical count for v6reply field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6request | Specifies the numerical count for v6request field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_nc_v6solicit | Specifies the numerical count for v6solicit field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_FREE_ADDRESSES | Specifies the sum for FREE_ADDRESSES field | si_dhcp_usage_trend | Splunk added special field | ||
psrsvd_sm_dhcp_utilization | Specifies the sum for dhcp_utilization field | si_dhcp_range_utilization_trend | Splunk added special field | ||
psrsvd_sm_dynamic_hosts | Specifies the sum for dynamic_hosts field | si_dhcp_usage_trend | Splunk added special field | ||
psrsvd_sm_static_hosts | Specifies the sum for static_hosts field | si_dhcp_usage_trend | Splunk added special field | ||
psrsvd_sm_v4ack | Specifies the sum for v4ack field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v4decline | Specifies the sum for v4decline field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v4discover | Specifies the sum for v4discover field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v4inform | Specifies the sum for v4inform field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v4leaseactive | Specifies the sum for v4leaseactive field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v4leasequery | Specifies the sum for v4leasequery field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v4leaseunassigned | Specifies the sum for v4leaseunassigned field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v4leaseunknown | Specifies the sum for v4leaseunknown field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v4nak | Specifies the sum for v4nak field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v4offer | Specifies the sum for v4offer field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v4release | Specifies the sum for v4release field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v4request | Specifies the sum for v4request field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6advertise | Specifies the sum for v6advertise field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6confirm | Specifies the sum for v6confirm field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6decline | Specifies the sum for v6decline field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6information_request | Specifies the sum for v6information_request field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6leasequery | Specifies the sum for v6leasequery field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6leasequery_reply | Specifies the sum for v6leasequery_reply field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6rebind | Specifies the sum for v6rebind field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6reconfigure | Specifies the sum for v6reconfigure field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6relay_forward | Specifies the sum for v6relay_forward field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6relay_reply | Specifies the sum for v6relay_reply field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6release | Specifies the sum for v6release field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6renew | Specifies the sum for v6renew field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6reply | Specifies the sum for v6reply field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6request | Specifies the sum for v6request field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_sm_v6solicit | Specifies the sum for v6solicit field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_v | Here, v = version. This is not scoped to a single field. | si_dhcp_usage_trend, | Splunk added special field | ||
psrsvd_vt_FREE_ADDRESSES | Contains precision of the FREE_ADDRESSES field | si_dhcp_usage_trend | Splunk added special field | ||
psrsvd_vt_dhcp_utilization | Contains precision of the dhcp_utilization field | si_dhcp_range_utilization_trend | Splunk added special field | ||
psrsvd_vt_dynamic_hosts | Contains precision of the dynamic_hosts field | si_dhcp_usage_trend | Splunk added special field | ||
psrsvd_vt_static_hosts | Contains precision of the static_hosts field | si_dhcp_usage_trend | Splunk added special field | ||
psrsvd_vt_v4ack | Contains precision of the v4ack field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v4decline | Contains precision of the v4decline field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v4discover | Contains precision of the v4discover field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v4inform | Contains precision of the v4inform field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v4leaseactive | Contains precision of the v4leaseactive field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v4leasequery | Contains precision of the v4leasequery field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v4leaseunassigned | Contains precision of the v4leaseunassigned field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v4leaseunknown | Contains precision of the v4leaseunkown field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v4nak | Contains precision of the v4nak field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v4offer | Contains precision of the v4offer field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v4release | Contains precision of the v4release field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v4request | Contains precision of the v4request field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6advertise | Contains precision of the v6advertise field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6confirm | Contains precision of the v6confirm field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6decline | Contains precision of the v6decline field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6information_request | Contains precision of the v6information_request field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6leasequery | Contains precision of the v6leasequery field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6leasequery_reply | Contains precision of the v6leasequery_reply field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6rebind | Contains precision of the v6rebind field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6reconfigure | Contains precision of the v6reconfigure field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6relay_forward | Contains precision of the v6relay_forward field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6relay_reply | Contains precision of the v6relay_reply field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6release | Contains precision of the v6release field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6renew | Contains precision of the v6renew field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6reply | Contains precision of the v6reply field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6request | Contains precision of the v6request field | si-search-dhcp-message | Splunk added special field | ||
psrsvd_vt_v6solicit | Contains precision of the v6solicit field | si-search-dhcp-message | Splunk added special field | ||
report | Name of the report that is populating the summary index | ||||
DHCP Message Rate Trend data | si-search-dhcp-message | ||||
DHCPv4 Usage Trend data | si_dhcp_usage_trend | ||||
DHCP Top Lease Clients report data | si_dhcp_top_lease_client | ||||
Top Devices Denied an IP Address report data | si_devices_denied_an_ip_address | ||||
DHCPv4 Range Utilization Trend | si_dhcp_range_utilization_trend | ||||
Device and Device Classes reports data | si_dhcp_top_os_by_network | ||||
search_name | Common summary index fields | ||||
search_now | Common summary index fields | ||||
source | Splunk Default field | ||||
sourcetype | Splunk Default field | ||||
splunk_server | Splunk Default field | ||||
splunk_server_group | Splunk Default field | ||||
start_address | Specifies the start IP address | IP address | Infoblox DHCP summary | ||
timeendpos | Common extracted fields | ||||
timestartpos | Common extracted fields | ||||
View | Specifies the network view | String. Example: default | Infoblox DHCP summary |
...
Extracted Field Name | Description of the field | Reports | Values/Range | Source of Data | Remarks |
EA | Common Extracted fields | ||||
HWTYPE | Common Extracted fields | ||||
MAX_DB_OBJECTS | Common Extracted fields | ||||
MAX_DHCP_LPS | Common Extracted fields | ||||
MAX_DNS_QPS | Common Extracted fields | ||||
MEMBER_IP | Common Extracted fields | ||||
date_hour | Splunk Default field | ||||
date_mday | Splunk Default field | ||||
date_minute | Splunk Default field | ||||
date_month | Splunk Default field | ||||
date_second | Splunk Default field | ||||
date_wday | Splunk Default field | ||||
date_year | Splunk Default field | ||||
date_zone | Splunk Default field | ||||
eventtype | Splunk Default field | ||||
host | Splunk Default field | ||||
index | Splunk Default field | ||||
info_max_time | Common summary index fields | ||||
info_min_time | Common summary index fields | ||||
info_search_time | Common summary index fields | ||||
linecount | Splunk Default field | ||||
Monitor | Specifies the monitor | String. Example: https | Infoblox DTC summary | ||
orig_host | Specifies the host name of the data source | Example: infoblox.com | Splunk added default field | ||
pool | Specifies the Pool | String. Example: Pool | Infoblox DTC summary | ||
psrsvd_ct_available | Specifies the count information for available field | si_adns_resource_pool_availability and | Splunk added special field | ||
psrsvd_ct_response_count | Specifies the count information for response_count field | si_dtc_response_distribution | Splunk added special field | ||
psrsvd_ct_unavailable | Specifies the count information for unavailable field | si_adns_resource_pool_availability and | Splunk added special field | ||
psrscd_ct_value | Specifies the count information for value field | si_smart_dns_resource_snmp | Splunk added special field | ||
psrsvd_gc | Here, gc = group count. This is the count for stats " grouping " and not scoped to a single field. | si_dtc_response_distribution, | Splunk added special field | ||
psrsvd_nc_available | Specifies the numerical count information for available field | si_adns_resource_pool_availability and | Splunk added special field | ||
psrsvd_nc_response_count | Specifies the numerical count information for response_count field | si_dtc_response_distribution | Splunk added special field | ||
psrsvd_nc_unavailable | Specifies the numerical count information for unavailable field | si_adns_resource_pool_availability and | Splunk added special field | ||
psrsvd_nc_value | Specifies the numerical count information for value field | si_smart_dns_resource_snmp | Splunk added special field | ||
psrsvd_sm_available | Specifies the sum information for available field | si_adns_resource_pool_availability and | Splunk added special field | ||
psrsvd_sm_response_count | Specifies the sum information for response_count field | si_dtc_response_distribution | Splunk added special field | ||
psrsvd_sm_unavailable | Specifies the sum information for unavailable field | si_adns_resource_pool_availability and | Splunk added special field | ||
psrsvd_sm_value | Specifies the sum information for value field | si_smart_dns_resource_snmp | Splunk added special field | ||
psrsvd_v | Here, v = version. This is not scoped to a single field. | si_dtc_response_distribution, | Splunk added special field | ||
psrsvd_vt_available | Contains precision of the available field | si_adns_resource_pool_availability and | Splunk added special field | ||
psrsvd_vt_response_count | Contains precision of the response_count field | si_dtc_response_distribution | Splunk added special field | ||
psrsvd_vt_unavailable | Contains precision of the unavailable field | si_adns_resource_pool_availability and | Splunk added special field | ||
psrsvd_vt_value | Contains precision of the value field | si_smart_dns_resource_snmp | Splunk added special field | ||
report | Name of the report that populates the summary index | ||||
DNS Traffic Control Response Distribution Trend data | si_dtc_response_distribution | ||||
DNS Traffic Control Resource Pool Availability reports data | si_adns_resource_pool_availability | ||||
DNS Traffic Control Resource SNMP reports data | si_smart_dns_resource_snmp | ||||
DNS Traffic Control Resource Availability reports data | si_smart_dns_resource_availability | ||||
resource | Specifies the resource | String. Example: Server | Infoblox DTC summary | ||
search_name | Common summary index fields | ||||
search_now | Common summary index fields | ||||
source | Splunk Default field | ||||
sourcetype | Splunk Default field | ||||
splunk_server | Splunk Default field | ||||
splunk_server_group | Splunk Default field | ||||
timeendpos | Common extracted fields | ||||
timestartpos | Common extracted fields |
...
Extracted Field Name | Description of the field | Reports | Values/Range | Source of Data | Remarks |
EA | Common Extracted fields | ||||
HWTYPE | Common Extracted fields | ||||
MAX_DB_OBJECTS | Common Extracted fields | ||||
MAX_DHCP_LPS | Common Extracted fields | ||||
MAX_DNS_QPS | Common Extracted fields | ||||
MEMBER | Specifies the member | String. Example: infoblox.localdomain: inbound | Evaluated from the host and sys_report_id field values | ||
MEMBER_IP | Common Extracted fields | ||||
date_hour | Splunk Default field | ||||
date_mday | Splunk Default field | ||||
date_minute | Splunk Default field | ||||
date_month | Splunk Default field | ||||
date_second | Splunk Default field | ||||
date_wday | Splunk Default field | ||||
date_year | Splunk Default field | ||||
date_zone | Splunk Default field | ||||
eventtype | Splunk Default field | ||||
host | Splunk Default field | ||||
index | Splunk Default field | ||||
info_max_time | Common summary index fields | ||||
info_min_time | Common summary index fields | ||||
info_search_time | Common summary index fields | ||||
linecount | Splunk Default field | ||||
orig_host | Specifies the host name of the data source | Example: infoblox.com | Splunk added default field | ||
psrsvd_ct_CPU_PERCENT | Specifies the count information for the CPU_PERCENT field | si_cpu_usage | Splunk added special field | ||
psrsvd_ct_MEMORY_PERCENT | Specifies the count information for the MEMORY_PERCENT field | si_memory_utilization | Splunk added special field | ||
psrsvd_ct_TRAF_VALUE | Specifies the count information for TRAF_VALUE field | si_traffic_rate | Splunk added special field | ||
psrsvd_gc | Here, gc = group count. This is the count for a stats " grouping, " and not scoped to a single field. | si_memory_utilization and si_traffic_ratesi_cpu_usage | Splunk added special field | ||
psrsvd_nc_CPU_PERCENT | Specifies the numerical count information for CPU_PERCENT field | si_cpu_usage | Splunk added special field | ||
psrsvd_nc_MEMORY_PERCENT | Specifies the numerical count information for MEMORY_PERCENT field | si_memory_utilization | Splunk added special field | ||
psrsvd_nc_TRAF_VALUE | Specifies the numerical count information for TRAF_VALUE field | si_traffic_rate | Splunk added special field | ||
psrsvd_sm_CPU_PERCENT | Specifies the sum for CPU_PERCENT field | si_cpu_usage | Splunk added special field | ||
psrsvd_sm_MEMORY_PERCENT | Specifies the sum for MEMORY_PERCENT field | si_memory_utilization | Splunk added special field | ||
psrsvd_sm_TRAF_VALUE | Specifies the sum for TRAF_VALUE field | si_traffic_rate | Splunk added special field | ||
psrsvd_v | Here, v = version. This is not scoped to a single field. | si_memory_utilization, si_traffic_rate, and si_cpu_usage | Splunk added special field | ||
psrsvd_vt_CPU_PERCENT | Contains precision of the CPU_PERCENT field | si_cpu_usage | Splunk added special field | ||
psrsvd_vt_MEMORY_PERCENT | Contains precision of the MEMORY_PERCENT field | si_memory_utilization | Splunk added special field | ||
psrsvd_vt_TRAF_VALUE | Contains precision of the TRAF_VALUE field | si_traffic_rate | Splunk added special field | ||
report | Specifies the name of the report that is populating the summary index | ||||
Index Disk Usage Report Data | si_index_disk_usage | ||||
Memory Utilization Trend data | si_memory_utilization | ||||
Traffic Rate by Member report data | si_traffic_rate | ||||
CPU Utilization Trend data | si_cpu_usage | ||||
search_name | Common summary index fields | ||||
search_now | Common summary index fields | ||||
source | Splunk Default field | ||||
sourcetype | Splunk Default field | ||||
splunk_server | Splunk Default field | ||||
splunk_server_group | Splunk Default field | ||||
timeendpos | Common extracted fields | ||||
timestartpos | Common extracted fields |
...