All Apps and Add-ons

Destination/Server IP in a log

jurij_hatala
New Member

Would it be possible to have a destination / server IP field in a log?
How it's could be configured?

0 Karma

PavelP
Motivator

Hello Jurij,
add to the log dest_ip=IP.toString(URL.dstIP)

Beware that this property triggers a DNS lookup.

Best regards
Pavel

0 Karma

jaxjohnny2000
Builder

Thank you. We'll try that

0 Karma

PavelP
Motivator

Hi

You need to enable dest ip rule in the mwgaccess3.log configuration. The rule is already there, just enable it.
Go policy > log handler > mwgaccess3.log

0 Karma

jaxjohnny2000
Builder

there is a field called "dest_ip", but it does not bring back those values:

value count %
1 116 16.089%
1132 4 0.555%
1125 3 0.416%
1188 3 0.416%
1438 3 0.416%
517 3 0.416%
6647 3 0.416%
6653 3 0.416%
1008 2 0.277%
1042 2 0.277%

0 Karma

jaxjohnny2000
Builder

the props.conf has this:
FIELDALIAS-dest_ip = dst AS dest_ip
REPORT-dst = mwg_dst

Does the Destination IP even come over from McAfee Web Gateway?

the src_ip field works fine.

When you say add to the log, I need to ask the McAfee admins to add this?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...