Getting Data In

How to create a new field and assign the hostname field using IP address

martinnepolean
Explorer

Hi All,

We are getting data from an application server for all servers and we are getting the IP address in dest_ip field. Now we like to exclude the servers from Linux and it would be difficult to use an IP address to filter the event. So we are looking for a way to perform DNSlookups and assign the hostname in the new field so that I can easily exclude it using regex. Please let me know how to create a new field and assign the hostname into it.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I believe the OP wants to do DNS lookups at index time, not search time.

---
If this reply helps you, Karma would be appreciated.
0 Karma

martinnepolean
Explorer

Yeah, I like to perform dns lookup at index time

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...