Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents
maxLevel2
typeflat

...

Valid tags and data tables

The full tag must have 4 levels. The first two are fixed as ddi.infoblox. The third level identifies the type of events sent, and the fourth level indicates the event subtype. 

Technology

Brand

Type

Subtype

ddi

infoblox

  • audit


  • serialconsole

  • sshd

  • httpd

  • dhcp

  • dhcpd

  • validate_dhcpd

  • dns

  • general

  • client

  • config

  • dtc

  • lameServers

  • network

  • notify

  • queries

  • rateLimit

  • resolver

  • infobloxResponses

  • rpz

  • security

  • xferIn

  • xferOut

  • unknown

  • update

  • updateSecurity

  • nios

  • ntp

  • ntpdate

  • monitor

  • syslogNg

  • rabbitmq_control

...

Tag

Data table

ddi.infoblox.audit.serialconsole

ddi.infoblox.audit.serialconsole

ddi.infoblox.audit.sshd

ddi.infoblox.audit.sshd

ddi.infoblox.audit.httpd

ddi.infoblox.audit.httpd

ddi.infoblox.dhcp.dhcpd

ddi.infoblox.dhcp.dhcpd

ddi.infoblox.dhcp.validate_dhcpd

ddi.infoblox.dhcp.validate_dhcpd

ddi.infoblox.dns.general

ddi.infoblox.dns.general

ddi.infoblox.dns.client

ddi.infoblox.dns.client

ddi.infoblox.dns.config

ddi.infoblox.dns.config

ddi.infoblox.dns.database

ddi.infoblox.dns.database

ddi.infoblox.dns.dtc

ddi.infoblox.dns.dtc

ddi.infoblox.dns.lame-servers

ddi.infoblox.dns.lameServers

ddi.infoblox.dns.network

ddi.infoblox.dns.network

ddi.infoblox.dns.notify

ddi.infoblox.dns.notify

ddi.infoblox.dns.queries

ddi.infoblox.dns.queries

ddi.infoblox.dns.rate-limit

ddi.infoblox.dns.rateLimit

ddi.infoblox.dns.resolver

ddi.infoblox.dns.resolver

ddi.infoblox.dns.infoblox-responses

ddi.infoblox.dns.infobloxResponses

ddi.infoblox.dns.rpz

ddi.infoblox.dns.rpz

ddi.infoblox.dns.security

ddi.infoblox.dns.security

ddi.infoblox.dns.xfer-in

ddi.infoblox.dns.xferIn

ddi.infoblox.dns.xfer-out

ddi.infoblox.dns.xferOut

ddi.infoblox.dns.unknown

ddi.infoblox.dns.unknown

ddi.infoblox.dns.update

ddi.infoblox.dns.update

ddi.infoblox.dns.update-security

ddi.infoblox.dns.updateSecurity

ddi.infoblox.nios.ntpd

ddi.infoblox.nios.ntpd

ddi.infoblox.nios.ntpdate

ddi.infoblox.nios.ntpdate

ddi.infoblox.nios.monitor

ddi.infoblox.nios.monitor

ddi.infoblox.nios.syslog-ng

ddi.infoblox.nios.syslogNg

ddi.infoblox.nios.rabbitmq_control

ddi.infoblox.nios.rabbitmq_control

ddi.infoblox.unknown.unknown

ddi.infoblox.unknown.unknown

How is the data sent to Devo?

Set up the Devo relay rules

...

Infoblox DNS Logging Categories

Relay rule names

DDI Infoblox - DNS Categories

DDI Infoblox - DNS Category DTC 1

DDI Infoblox - DNS Category DTC 2

DDI Infoblox - unknown DNS Categories

general




client




config




database




dnssec




lame servers




network




notify




queries




rate-limit




resolver




responses




rpz




security




transfer-in




transfer-out




update




update-security




DTC load balancing




DTC health monitors




RulesRelay screenshot

DDI Infoblox - DNS Categories

  • Source Port → Customer source port, for example 13004

  • Source data → ^.*named\[\d*\]:\s+([\S]+):

  • Target Tag → ddi.infoblox.dns.\\d1

  • Sent without syslog tag → True

  • Is Prefix → False (by default)

  • Stop processing → True

Image Removed

DDI Infoblox - DNS Category DTC 2

  • Source Port → Customer source port, for example 13004

  • Source data → ^named\[\d*\]:\s+request\s

  • Target Tag → ddi.infoblox.dns.dtc

  • Sent without syslog tag → True

  • Is Prefix →False (by default)

  • Stop processing → True

Image Removed

DDI Infoblox - unknown DNS Categories

  • Source Port → Customer source port, for example 13004

  • Source data → ^(?:import_)?named\[\d*\]

  • Target Tag → ddi.infoblox.dns.unknown

  • Sent without syslog tag → True

  • Is Prefix → False (by default)

  • Stop processing → True

Image Removed

DDI Infoblox - DNS Category DTC 1

  • Source Port → Customer source port, for example 13004

  • Source data → ^idns_health

  • Target Tag → ddi.infoblox.dns.dtc

  • Sent without syslog tag → True

  • Is Prefix → False (by default)

  • Stop processing → True

Image Removed


Infoblox - DHCP

Rules

Relay screenshot

DDI Infoblox - DHCP

  • Source Port → Customer source port, for example 13004

  • Source data → ^.*(validate_dhcpd|dhcpd)

  • Target Tag → ddi.infoblox.dhcp.\\d1

  • Sent without syslog tag → True

  • Is Prefix → False (by default)

  • Stop processing → True

Image Removed

Infoblox - NIOS

Rules

Relay screenshot

DDI Infoblox - NIOS

  • Source Port → Customer source port, for example 13004

  • Source data → ^(ntpdate|monitor|ntpd|rabbitmq_control|syslog-ng)

  • Target Tag → ddi.infoblox.nios.\\d1

  • Sent without syslog tag → True

  • Is Prefix → False (by default)

  • Stop processing → True

Image Removed

Infoblox - Audit

Rules

Relay screenshot

DDI Infoblox - AUDIT

  • Source Port → Customer source port, for example 13004

  • Source data → ^.*(serial_console|httpd|sshd)

  • Target Tag → ddi.infoblox.audit.\\d1

  • Sent without syslog tag → True

  • Is Prefix → False (by default)

  • Stop processing → True

Image Removed

Infoblox - unknown

Rules

Relay screenshot

DDI Infoblox - unknown

  • Source Port → Customer source port, for example 13004

  • Target Tag → ddi.infoblox.unknown.unknown

  • Sent without syslog tag → True

  • Is Prefix → False (by default)

  • Stop processing → True

Image Removed

Configure Infoblox NIOS to send logs to the Relay

...

  1. Select Data Management tab

  2. Select the DNS tab

  3. Click Grid DNS Properties from the Toolbar

  4. Enable de Advanced Mode by clicking on “Toggle Expert Mode” if the editor is in the basic mode.

  5. Select the Logging tab

  6. Select the Logging Categories you would like to send to Devo.

  7. Save & Close

Note

Enabling some logging categories can increase disk space usage and adversely affect DNS services and performance. Check with Infoblox whether you are recommended to logging some of these categories.

...

After saving the changes, you may be prompted to restart the DNS service for the changes to take effect.

...