<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alert based on domain name, not IP in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Alert-based-on-domain-name-not-IP/m-p/59071#M14558</link>
    <description>&lt;P&gt;We would like to setup an alert based upon domain name -- that is, our apache logs contain IP addresses of the GET request.  Can an alert be set that matches on a domain name and if so, what transforms or other methods need to be implemented to do so.&lt;/P&gt;

&lt;P&gt;I'm guessing that if the apache logs would do dns lookups, they would then contain the domain name and that could work -- as long as I can trigger an alert based on domain names contained in the apache logs. &lt;/P&gt;

&lt;P&gt;Otherwise can splunk -- and would I even want splunk -- to do the domain lookups and then report accordingly?&lt;/P&gt;

&lt;P&gt;Thank you. &lt;/P&gt;</description>
    <pubDate>Thu, 24 May 2012 03:55:10 GMT</pubDate>
    <dc:creator>bulgin</dc:creator>
    <dc:date>2012-05-24T03:55:10Z</dc:date>
    <item>
      <title>Alert based on domain name, not IP</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Alert-based-on-domain-name-not-IP/m-p/59071#M14558</link>
      <description>&lt;P&gt;We would like to setup an alert based upon domain name -- that is, our apache logs contain IP addresses of the GET request.  Can an alert be set that matches on a domain name and if so, what transforms or other methods need to be implemented to do so.&lt;/P&gt;

&lt;P&gt;I'm guessing that if the apache logs would do dns lookups, they would then contain the domain name and that could work -- as long as I can trigger an alert based on domain names contained in the apache logs. &lt;/P&gt;

&lt;P&gt;Otherwise can splunk -- and would I even want splunk -- to do the domain lookups and then report accordingly?&lt;/P&gt;

&lt;P&gt;Thank you. &lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2012 03:55:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Alert-based-on-domain-name-not-IP/m-p/59071#M14558</guid>
      <dc:creator>bulgin</dc:creator>
      <dc:date>2012-05-24T03:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Alert based on domain name, not IP</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Alert-based-on-domain-name-not-IP/m-p/59072#M14559</link>
      <description>&lt;P&gt;This is something that you can have Splunk do via a look up which could be a .csv file or better yet a script in this case. See this for reference.  You can set up the look up to be automatic or manual via search.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://blogs.splunk.com/2009/12/15/reverse-dns-lookups-for-host-entries/"&gt;http://blogs.splunk.com/2009/12/15/reverse-dns-lookups-for-host-entries/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Look ups in the docs: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/lookup"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/lookup&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Example in the docs referencing hostname look up: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsfromexternaldatasources"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsfromexternaldatasources&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2012 12:44:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Alert-based-on-domain-name-not-IP/m-p/59072#M14559</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-05-24T12:44:56Z</dc:date>
    </item>
  </channel>
</rss>

