Getting Data In

Mac address from IP or host

Celeste
Engager

I'm very new to Splunk, so if this is a over simple question please bear with me.

I need to find the mac addresses for each of our remote servers. Is there a search where I can give an IP address or a host name and get back the mac address(es) related to it?

Thanks in advance!!

Tags (3)
0 Karma

Celeste
Engager

Thanks to both of you for the answers. I'm new to the IT world, so this is meant as a "learning task." Every bit of info helps.

Just got another bread crumb: I'll be correlating /var/logs to get my answers. Goal for tomorrow: figure out where our /var/logs live and how to get what I need out of them!

Thanks again,
Celeste

0 Karma

richgalloway
SplunkTrust
SplunkTrust

For the most part, you get out of Splunk what you put into it. That is, if you have a data source that is saving MAC addresses in a Splunk index then you should be able to search for a given host and get the associated MAC address. Without knowing more about your environment, it is difficult to give specifics.

---
If this reply helps you, Karma would be appreciated.

sbrant_splunk
Splunk Employee
Splunk Employee

Depending on your environment, you should be able to get the MAC/IP pairings from DHCP server logs. I say that it depends because you may not be using DHCP to statically assign IP addresses to servers. Another option would be to have Splunk forwarders on your servers, that utilize a scripted input (ifconfig for nix or ipconfig for Windows).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...