<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search results - How to prevent DNS resolution in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-DNS-resolution/m-p/631696#M219401</link>
    <description>&lt;P&gt;What do you mean by "the results in Splunk is changing the IP addresses to their respective hostnames/FQDNs"? Where?&lt;/P&gt;&lt;P&gt;Most probably you mistake the metadata field associated with an event with data contained in the event.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Feb 2023 11:34:19 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2023-02-21T11:34:19Z</dc:date>
    <item>
      <title>How to prevent DNS resolution?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-DNS-resolution/m-p/631693#M219398</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;
&lt;P&gt;Our raw syslogs are showing IP addresses of sourced events, but the results in Splunk is changing the IP addresses to their respective hostnames/FQDNs.&lt;/P&gt;
&lt;P&gt;If I want to see the results without the name resolution how can I do this? I just need to see the IP addresses, as per the actual raw syslog.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Will&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 17:55:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-DNS-resolution/m-p/631693#M219398</guid>
      <dc:creator>willspk</dc:creator>
      <dc:date>2023-02-21T17:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Search results - How to prevent DNS resolution</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-DNS-resolution/m-p/631694#M219399</link>
      <description>&lt;P&gt;Hi, I guess you're receiving syslog data directly on a data collection node like a heavy forwarder if yes you could configure following parameter in your inputs.conf&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;connection_host = [ip|dns|none]
* How the network input sets the host field for the events it generates.
* A value of "ip" sets the host to the IP address of the system sending the data.
* A value of "dns" sets the host to the reverse DNS entry for the IP address of
  the system that sends the data. For this to work correctly, set the forward
  DNS lookup to match the reverse DNS lookup in your DNS configuration.
* A value of "none" leaves the host as specified in inputs.conf, typically the
  hostname of the system running Splunk software.
* Default: dns&lt;/LI-CODE&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.4/Admin/Inputsconf#TCP:_Transport_Control_Protocol_.28TCP.29_network_inputs" target="_blank"&gt;inputs.conf - Splunk Documentation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 11:04:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-DNS-resolution/m-p/631694#M219399</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2023-02-21T11:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: Search results - How to prevent DNS resolution</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-DNS-resolution/m-p/631696#M219401</link>
      <description>&lt;P&gt;What do you mean by "the results in Splunk is changing the IP addresses to their respective hostnames/FQDNs"? Where?&lt;/P&gt;&lt;P&gt;Most probably you mistake the metadata field associated with an event with data contained in the event.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 11:34:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-DNS-resolution/m-p/631696#M219401</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-02-21T11:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Search results - How to prevent DNS resolution</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-DNS-resolution/m-p/631728#M219413</link>
      <description>&lt;P&gt;Yea, what we're using for Syslog collection is doing the name resolution. Not Splunk. I swear I deleted this as soon as I realised my mistake!&lt;/P&gt;&lt;P&gt;Thanks for the input nonetheless.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 14:34:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-DNS-resolution/m-p/631728#M219413</guid>
      <dc:creator>willspk</dc:creator>
      <dc:date>2023-02-21T14:34:40Z</dc:date>
    </item>
  </channel>
</rss>

