If you need something for POC / smoke: https://github.com/m3047/shodohflo/blob/master/examples/dnstap2json.py Assuming you can figure out how to get Splunk to consume log oriented json over UDP... -- Fred Morris, internet plumber