All Apps and Add-ons

Exchange App: getting unknown domain

mikelanghorst
Motivator

I've installed the Splunk for Exchange app. One of the issues I'm having is with users showing up with @unknown.

I've created the domain_aliases.csv on the search head, with UNKNOWN, unknown, and our netbios name, and our domain name. But it's still showing mlanghorst@unknown.

I have 2 indexers and one search head. I've thought that maybe this needs to go on the indexer, but according to the docs I should only need to install the TA* apps there.

What am I missing here? Not sure yet what records that this search is keying off of.

0 Karma

davidts
Path Finder

I have the same issue as OP. Was there a resolution to this? My NetBios names are not being translated to the domain and I have my domain_aliases.csv file in the "local" folder of the Exchange app on my Search Head. The format of my CSV file is similar that of OP.

Thanks.

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Hey DavidTS,

You are not having the same problem as OP as the fix suggested repaired his problem. Open up a new question and don't forget to include your Splunk version, Exchange app version, OS version and a copy of your domain_aliases.csv file!

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Let's say you had a domain "SPLUNK" which is really "splunk.com", then your domain_aliases.csv file would look like this:

UNKNOWN,splunk.com
SPLUNK,splunk.com

If you have

UNKNOWN,unknown
SPLUNK,splunk.com

then you would see what you are seeing.

0 Karma

mikelanghorst
Motivator

UNKNOWN,caiso.com
unknown,caiso.com
ISOOA1,caiso.com

I put the lower case unknown in there after UNKNOWN didn't work. ISOOA1 is our netbios name. Yet they're still showing up as mlanghorst@unknown.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...