Getting Data In

Mac address from IP or host

Celeste
Engager

I'm very new to Splunk, so if this is a over simple question please bear with me.

I need to find the mac addresses for each of our remote servers. Is there a search where I can give an IP address or a host name and get back the mac address(es) related to it?

Thanks in advance!!

Tags (3)
0 Karma

Celeste
Engager

Thanks to both of you for the answers. I'm new to the IT world, so this is meant as a "learning task." Every bit of info helps.

Just got another bread crumb: I'll be correlating /var/logs to get my answers. Goal for tomorrow: figure out where our /var/logs live and how to get what I need out of them!

Thanks again,
Celeste

0 Karma

richgalloway
SplunkTrust
SplunkTrust

For the most part, you get out of Splunk what you put into it. That is, if you have a data source that is saving MAC addresses in a Splunk index then you should be able to search for a given host and get the associated MAC address. Without knowing more about your environment, it is difficult to give specifics.

---
If this reply helps you, Karma would be appreciated.

sbrant_splunk
Splunk Employee
Splunk Employee

Depending on your environment, you should be able to get the MAC/IP pairings from DHCP server logs. I say that it depends because you may not be using DHCP to statically assign IP addresses to servers. Another option would be to have Splunk forwarders on your servers, that utilize a scripted input (ifconfig for nix or ipconfig for Windows).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...