All Apps and Add-ons

How can I run a whois search on multiple IPs with one command?

Explorer

Using the Network Toolkit app, I want to run the whois command on multiple IPs with one command, such as reading from a lookup. Is that possible?

i.e. |whois IP1, IP2, IP3

1 Solution

Champion

You use the whois lookup command that is included in the Network Toolkit app. See (https://lukemurphey.net/projects/network-tools/wiki/Using_Lookups).

For example, your search may end with the lookup command like this:

... | lookup whois host as host_to_lookup | table _raw host raw updated_date nameservers registrar whois_server query creation_date emails expiration_date status id

View solution in original post

0 Karma

Champion

You use the whois lookup command that is included in the Network Toolkit app. See (https://lukemurphey.net/projects/network-tools/wiki/Using_Lookups).

For example, your search may end with the lookup command like this:

... | lookup whois host as host_to_lookup | table _raw host raw updated_date nameservers registrar whois_server query creation_date emails expiration_date status id

View solution in original post

0 Karma

New Member

Hi Luke,

I'm trying to use the lookup as you have it here, but all of those fields come out blank. The only fields that return anything are _raw and host. Additionally if I do | table * then contact.address contact.email contact.name contact.phone all return with the correct results, but not other fields from the whois lookup populate. Is there something I am doing wrong?

0 Karma

Path Finder

I also can't get this to work. Hopefully, someone has a solution.

0 Karma

Communicator

It happens the same to me too.
Could someone correct it? please!

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!