Getting Data In

Can local hosts-file be used instead of reverse DNS

thoree
Explorer

Hi,

My Splunk-server receives syslogs from a number of devices that are not registered in reverse dns, therefore the events in Splunk shows the ipaddress, not the hostname. Is it possible to configure Splunk to use its local hosts-file to resolve the names? So that I can register all the devises in the local hosts-file to resolve the problem?

Tags (2)
0 Karma

tgow
Splunk Employee
Splunk Employee

This is typically configured on the OS of the system on the order of name resolution. If you configure the following on the inputs.conf file for the syslog input:

[udp://<remote server>:<port>]
connection_host = dns

The /etc/nsswitch.conf file has the order information for name resolution. Here is an example:

hosts: dns files

The gethostbyname library will look first to resolve the name with dns and if it does not find an answer then it will look at the local /etc/hosts next.

Hope this helps.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...