---
title: "Sourcetypes"
canonical: "https://docs.infoblox.com/space/DeploymentGuideInfobloxAppforSplunk/774963542/Sourcetypes"
format: markdown
---
The Infoblox App For Splunk provides the search-time knowledge for Infoblox data in the following formats:

|  |  |
| --- | --- |
| **Sourcetype** | **Description** |
| ib:dns:captures | This sourcetype will have data for dns (Splunk CIM). |
| ib:audit:captures | This sourcetype will have data for audit (Splunk CIM). |
| ib:dhcp:captures | This sourcetype will have data for dhcp (Splunk CIM). |
| ib:rpz:captures | This sourcetype will have data for blocked DNS (Splunk CIM). |
| ib:service:captures | This sourcetype will have data for service (Splunk CIM). |
| ib:socinsights:captures | This sourcetype will have data for soc insights (Splunk CIM). |
| ib:notifications:captures | This sourcetype will have data for internal notifications (Splunk CIM). |
| infoblox:tide_host | This sourcetype will contain the host information (API). |
| infoblox:tide_ip | This sourcetype will contain the ip information (API). |
| infoblox:tide_url | This sourcetype will contain the url information (API). |
| infoblox:tide_hash | This sourcetype will contain the hash information (API). |
| infoblox:tide_email | This sourcetype will contain the email information (API). |
| infoblox:soc_insights | This sourcetype will contain the soc insights details (API). |
| infoblox_soc_insights_assets | This sourcetype will contain the soc insights asset details (API). |
| infoblox_soc_insights_events | This sourcetype will contain the soc insights events details (API). |
| infoblox_soc_insights_indicators | This sourcetype will contain the soc insights indicator details (API). |
| infoblox_soc_insights_comments | This sourcetype will contain the soc insights comment details (API). |