Getting Data In

How can I extract Hostname Field via IP address in event info from .csv lookup?

adam_dixon95
Explorer

Hi,

I'm looking at alerting on SNMP traps in Splunk and one thing that I need to do is to be able to lookup the hostname from the IP address listed in the event - the hostname will be pulled via a .csv.

The csv has the following columns with data populated underneath:

customer_hostname,customer_IP

SNMP trap information shows the customer IP address of the device, but I need the hostname to be pulled from the .csv and added to a field/event info so we can see the hostname clearly.

Any information on how to this would be greatly appreciated.

gcusello
SplunkTrust
SplunkTrust

Hi,

If you have a lookup with IPs and hostnames you can use the lookup command:

Your_search
| lookup my_lookup.csv IP OUTPUT hostname
| ...

If instead you can access the DNS you can use the dnslookup command.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...