All Apps and Add-ons

Problem resolving DNS outside of Domain name,



I´ve been working with lookup and its working fine, I used this :

" | lookup dnslookup clientip
as src OUTPUT clienthost | table _time clienthost src "

It can resolve Publics IPs by his www hostname but somehow the internal IP just resolve the IP that are within the windows Domains, the others IP that are internal but no in the domains, can not.

alt text

I tried to review the DNS ( cat /etc/resolv.conf) of the SPLUNK Search, and this is the results,

cat /etc/resolv.conf

[root@genosis ~]# cat /etc/resolv.conf

Generated by NetworkManager

[root@genosis ~]#

I tested in my Pc , that it has the same DNS and I got this result

alt text

Do you have any idea, how can I put this resolved address in the clienthost field?

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...