Help With RDNS For scr_ip in Syslog Message

New Member

I am trying to display the fqdn instead of the IP address for the internal host in a syslog message. In the example below, I would like to resolve the address to FQDN and display that in Splunk, instead of the IP address.

Any assistance would be greatly appreciated.

Jul 31 01:46:08 [] Jul 31 2012 01:46:08 EXT-FW : %ASA-4-338008: Dynamic Filter dropped blacklisted TCP traffic from inside: ( to outside: (, destination resolved from dynamic list:, threat-level: very-high, category: Malware
Tags (1)
0 Karma

Splunk Employee
Splunk Employee
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!