<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WHOIS Search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/WHOIS-Search/m-p/302359#M161874</link>
    <description>&lt;P&gt;I've looked at splunkbase for "whois" apps and searched the community for whois-type scripts, but found none that meet my needs.  What I would like is to find an app/script very similar to the Linux whois command.  This gives me all the information I need.  I've tried the Newtork Tools app, but whois is a geneating command so I can't use it in a search.  The generateblocklist_app &lt;A href="https://www.splunk.com/blog/2016/05/02/enriching-threat-feeds-with-whois-information-splunk.html"&gt;https://www.splunk.com/blog/2016/05/02/enriching-threat-feeds-with-whois-information-splunk.html&lt;/A&gt; doesn't provide enough information.  I can't create a commands.conf file and point to the bash whois command since it's not supported.  I don't want to use a limited free API or purchase an API.  Does anyone have ideas?  I'm needing to pass an IP instead of a domain name.  This will be very useful for creating a dashboard for threat hunting.  Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Wed, 04 Apr 2018 01:54:12 GMT</pubDate>
    <dc:creator>afarmer</dc:creator>
    <dc:date>2018-04-04T01:54:12Z</dc:date>
    <item>
      <title>WHOIS Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WHOIS-Search/m-p/302359#M161874</link>
      <description>&lt;P&gt;I've looked at splunkbase for "whois" apps and searched the community for whois-type scripts, but found none that meet my needs.  What I would like is to find an app/script very similar to the Linux whois command.  This gives me all the information I need.  I've tried the Newtork Tools app, but whois is a geneating command so I can't use it in a search.  The generateblocklist_app &lt;A href="https://www.splunk.com/blog/2016/05/02/enriching-threat-feeds-with-whois-information-splunk.html"&gt;https://www.splunk.com/blog/2016/05/02/enriching-threat-feeds-with-whois-information-splunk.html&lt;/A&gt; doesn't provide enough information.  I can't create a commands.conf file and point to the bash whois command since it's not supported.  I don't want to use a limited free API or purchase an API.  Does anyone have ideas?  I'm needing to pass an IP instead of a domain name.  This will be very useful for creating a dashboard for threat hunting.  Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Apr 2018 01:54:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WHOIS-Search/m-p/302359#M161874</guid>
      <dc:creator>afarmer</dc:creator>
      <dc:date>2018-04-04T01:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: WHOIS Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WHOIS-Search/m-p/302360#M161875</link>
      <description>&lt;P&gt;You could try scripted input to trigger your command and output the results to splunk and search it&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3/Developer/ScriptSetup"&gt;http://docs.splunk.com/Documentation/Splunk/4.3/Developer/ScriptSetup&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Apr 2018 06:47:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WHOIS-Search/m-p/302360#M161875</guid>
      <dc:creator>splunker12er</dc:creator>
      <dc:date>2018-04-04T06:47:50Z</dc:date>
    </item>
  </channel>
</rss>

