I am running a basic search and wanting to perform a reverse DNS lookup.
index=*proxy src_ip="10.x.x.x" | lookup dnslookup clientip as src_ip OUTPUT clienthost as Hostname
| table Hostname
The search is not returning any fields named Hostname. What am I missing? Is there a way to validate the external lookup python script is working?
Transforms.conf
[dnslookup]
external_cmd = external_lookup.py clienthost clientip
fields_list = clienthost,clientip
Splunk 6.6.2
Try this:
| makeresults | eval host="70.90.168.114" | lookup dnslookup clientip AS host
This should give you mail.ubcomputer.com
.
This works for external dns lookups. Is there a way to configure to work for internal resolution?
make sure that the host OS for your Search Head is using your internal DNS Server.