Getting Data In

How can I extract Hostname Field via IP address in event info from .csv lookup?

adam_dixon95
Explorer

Hi,

I'm looking at alerting on SNMP traps in Splunk and one thing that I need to do is to be able to lookup the hostname from the IP address listed in the event - the hostname will be pulled via a .csv.

The csv has the following columns with data populated underneath:

customer_hostname,customer_IP

SNMP trap information shows the customer IP address of the device, but I need the hostname to be pulled from the .csv and added to a field/event info so we can see the hostname clearly.

Any information on how to this would be greatly appreciated.

gcusello
SplunkTrust
SplunkTrust

Hi,

If you have a lookup with IPs and hostnames you can use the lookup command:

Your_search
| lookup my_lookup.csv IP OUTPUT hostname
| ...

If instead you can access the DNS you can use the dnslookup command.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...