Getting Data In

How can one get the host and source IP addresses in the event logs instead of hostname ?

sahil_singh
Explorer

Hi,

How can one get the host and source IP addresses in the event logs instead of hostname in either places. It is causing an issue regarding the analysis of the logs. Additionally is there an option for alert email generation, when the alert is high.

0 Karma

Ayn
Legend

You can do this by using an external lookup script that gets the corresponding IP address from the DNS entry. There's a script that's included with Splunk as an example that does just this. More information is available here: http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsfromexternaldatasources

sahil_singh
Explorer

hello can somebody help me here ?

0 Karma

sahil_singh
Explorer

yes...I downlaoded and ran universal forwarder onto two CPUs and am collecting logs from there. This is what it is showing as a result. If I search for telnet events of one CPU.

0 Karma

Ayn
Legend

How are you receiving these logs? From Universal Forwarders?

0 Karma

sahil_singh
Explorer

The telnet session will occur between two CPU. So isn't there an option of having IPs of both machines rather than have the name. Since identification process would far more easier and less time consuming.

0 Karma

sahil_singh
Explorer

for eg. There is a telnet session which takes place between two PCs in the network. Rather than having a hostname=CPU-WS2 representing that session. Is there an possibility that an IP could there instead ?

LogName=Security
SourceName=Security
EventCode=593
EventType=8
Type=Success Audit
ComputerName=CPU-WS2
User=CPU

Message=A process has exited:
Process ID:4732
Image File Name:C:\WINDOWS\system32\telnet.exe
User Name:CPU
Domain: CPU-WS2
Logon ID:(0x0,0xDD17)

host=CPU-ws2

Options|sourcetype=WinEventLog:Security

Options|source=WinEventLog:Security

Options|index=main Options

0 Karma

MarioM
Motivator

what you are trying is not very clear then could you paste the extract of your event and more detailed explanation

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...