<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP address vs hostname in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45561#M8545</link>
    <description>&lt;P&gt;Michael Wilde did a blog on reverse dns lookups.  &lt;/P&gt;

&lt;P&gt;It is definitely worth a read.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://blogs.splunk.com/2009/12/15/reverse-dns-lookups-for-host-entries/"&gt;http://blogs.splunk.com/2009/12/15/reverse-dns-lookups-for-host-entries/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jul 2011 13:00:55 GMT</pubDate>
    <dc:creator>Jodge</dc:creator>
    <dc:date>2011-07-20T13:00:55Z</dc:date>
    <item>
      <title>IP address vs hostname</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45559#M8543</link>
      <description>&lt;P&gt;Dear Splunkers,&lt;/P&gt;

&lt;P&gt;We recently have set up SPLUNK as a syslog to gather all the logs of our Cisco routers and switches. We just opened port 514 on splunk to start indexing everything.&lt;/P&gt;

&lt;P&gt;Logs are comming in, but all devices are shown by IP address.&lt;/P&gt;

&lt;P&gt;Now, my question is how to resolve these IP addresses too there hostname. It's not possible through DNS. &lt;/P&gt;

&lt;P&gt;But perhaps there is an other possibility that I don't know off.&lt;/P&gt;

&lt;P&gt;Any help or walktroughs are very welcome.&lt;/P&gt;

&lt;P&gt;Kind reagrds&lt;BR /&gt;
A follower&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2011 11:51:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45559#M8543</guid>
      <dc:creator>pereest</dc:creator>
      <dc:date>2011-07-20T11:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: IP address vs hostname</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45560#M8544</link>
      <description>&lt;P&gt;You can create a lookup file or add a hosts file to your server and splunk will use either of these to get the hostname.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2011 12:36:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45560#M8544</guid>
      <dc:creator>BobM</dc:creator>
      <dc:date>2011-07-20T12:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: IP address vs hostname</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45561#M8545</link>
      <description>&lt;P&gt;Michael Wilde did a blog on reverse dns lookups.  &lt;/P&gt;

&lt;P&gt;It is definitely worth a read.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://blogs.splunk.com/2009/12/15/reverse-dns-lookups-for-host-entries/"&gt;http://blogs.splunk.com/2009/12/15/reverse-dns-lookups-for-host-entries/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2011 13:00:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45561#M8545</guid>
      <dc:creator>Jodge</dc:creator>
      <dc:date>2011-07-20T13:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: IP address vs hostname</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45562#M8546</link>
      <description>&lt;P&gt;Lookup files work, if you can not use reverse DNS&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2011 13:25:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45562#M8546</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2011-07-20T13:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: IP address vs hostname</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45563#M8547</link>
      <description>&lt;P&gt;Due to our environment, we do IPs.  Most of the machines [that I care about] I translate the IP to a cluster name at report time, via lookup.&lt;BR /&gt;
There are cases when I care about who is doing what, but most of the time I want to trend who, client clusters, is hitting our clusters.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2011 15:27:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45563#M8547</guid>
      <dc:creator>fk319</dc:creator>
      <dc:date>2011-07-20T15:27:49Z</dc:date>
    </item>
    <item>
      <title>Re: IP address vs hostname</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45564#M8548</link>
      <description>&lt;P&gt;I just thought I would post in here in regards to a question I have that is related. I have heard thay you can get cisco devices to syslog and include their hostname in the syslog message.&lt;BR /&gt;
So far I have not found out if this is correct. Does anyone have any experience with that.&lt;/P&gt;

&lt;P&gt;I realise you can do a dnslookup, or do a lookup table, but thought if this was possible it might make more sense to apply that config change to our devices instead of splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2013 01:13:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45564#M8548</guid>
      <dc:creator>CeJay</dc:creator>
      <dc:date>2013-07-02T01:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: IP address vs hostname</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45565#M8549</link>
      <description>&lt;P&gt;This just worked fantastically (v6.5).&lt;/P&gt;

&lt;P&gt;Just be aware of what version he's referring to v.s. yours, some directories changed, but you'll get the idea...&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 16:20:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IP-address-vs-hostname/m-p/45565#M8549</guid>
      <dc:creator>Michael</dc:creator>
      <dc:date>2016-11-17T16:20:37Z</dc:date>
    </item>
  </channel>
</rss>

