All Apps and Add-ons

URL Toolbox: What is the most efficient way to map URLs with IPs to meaningful names to graph on a time chart?

caradoc
New Member

Using URL Toolbox to parse out ut_domain for varying levels of analysis - I've come up with a couple of different ways to map ut_domain to some meaningful name instead of winding up with a timechart of eight IP addresses all graphed separately with a few additional entries (google.com, apple.com, etc.), but I'm at a loss as to the most efficient way to do it. Making individual DNS queries for each unqualified IP in ut_domain is not very efficient. Placing a table of "if this is the IP in ut_domain, use this string instead for ut_domain" seems to work, but I have to think there's a better way.

Thoughts?

0 Karma

janderson19
Path Finder

You could put those IPs and their names into a lookup table. I personally don't know much about lookups buy you could try it

http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Lookup

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...