<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can both hostname and source IP be searchable? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Can-both-hostname-and-source-IP-be-searchable/m-p/87323#M22350</link>
    <description>&lt;P&gt;You can easily do it by &lt;A href="http://blogs.splunk.com/2009/12/15/reverse-dns-lookups-for-host-entries"&gt;using lookups.&lt;/A&gt; &lt;/P&gt;</description>
    <pubDate>Sat, 23 Apr 2011 09:33:36 GMT</pubDate>
    <dc:creator>IgorB</dc:creator>
    <dc:date>2011-04-23T09:33:36Z</dc:date>
    <item>
      <title>Can both hostname and source IP be searchable?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-both-hostname-and-source-IP-be-searchable/m-p/87322#M22349</link>
      <description>&lt;P&gt;Right now we have a lot of devices reporting syslogs into splunk. I'd really like to be able to search them by hostname or IP address. Is there a way to get both the IP address and the DNS lookup of the device into Splunk for the same syslog message?&lt;/P&gt;

&lt;P&gt;For instance if I have a device located at 172.16.57.1 and it's in DNS as YUM-CA-FW, then it would be nice to search for this device either way:&lt;BR /&gt;
host_ip="172.16.57.1"&lt;BR /&gt;
or&lt;BR /&gt;
host_name="YUM-CA-FW"&lt;/P&gt;

&lt;P&gt;Is this possible?&lt;/P&gt;

&lt;P&gt;If it is, can I take it a step further and have both a host_realIP and host_natIP?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:29:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-both-hostname-and-source-IP-be-searchable/m-p/87322#M22349</guid>
      <dc:creator>yumology</dc:creator>
      <dc:date>2020-09-28T09:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Can both hostname and source IP be searchable?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-both-hostname-and-source-IP-be-searchable/m-p/87323#M22350</link>
      <description>&lt;P&gt;You can easily do it by &lt;A href="http://blogs.splunk.com/2009/12/15/reverse-dns-lookups-for-host-entries"&gt;using lookups.&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Sat, 23 Apr 2011 09:33:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-both-hostname-and-source-IP-be-searchable/m-p/87323#M22350</guid>
      <dc:creator>IgorB</dc:creator>
      <dc:date>2011-04-23T09:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can both hostname and source IP be searchable?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-both-hostname-and-source-IP-be-searchable/m-p/87324#M22351</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
you can Get both Ip-Address and Host using the site &lt;A href="http://www.ip-details.com/"&gt;Ip-Details.com&lt;/A&gt; .They are accurate and Reliable.I usually do Ip-Search in this site.So I Prefer you to this site.It will be more Useful to you....&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2012 05:34:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-both-hostname-and-source-IP-be-searchable/m-p/87324#M22351</guid>
      <dc:creator>Horor</dc:creator>
      <dc:date>2012-08-28T05:34:37Z</dc:date>
    </item>
  </channel>
</rss>

