Getting Data In

dnslookup at index time

jflaherty
Path Finder

Hello,

I need have some windows logs that come in via forwarders that contain an IP address that I need to do a reverse lookup on.  You can easily do this at search time, however the the IP addresses in the log are DHCP and frequently change.  So i need to insert a field for the name at index time.  Is this possible?  I have read a previous post that said  there was not a way but it was an older post so I was wondering if it may be possible now?

Thanks

 

Labels (3)
0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!