Splunk Search

How to find out one of the host of ip adresses?

phanichintha
Path Finder

what is the command to find out one of the host name of Ip adress.

Tags (1)

FrankVl
Ultra Champion

Splunk has a built in 'external lookup' called dnslookup that you can use (assuming the address you want to lookup is in a field called ipAddress): | lookup dnslookup clientip as ipAddress

See also: https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/DefineanexternallookupinSplunkWeb#Exte...

0 Karma

jawaharas
Motivator
  1. Install the 'dnslookup' app - https://splunkbase.splunk.com/app/1535/
  2. Get host name of ip using below command

| dnslookup reverse ip host

0 Karma

FrankVl
Ultra Champion

No need to install a 6y old app for that. This functionality is built in nowadays 🙂

0 Karma

jawaharas
Motivator

Thanks. This also works.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...