Knowledge Management

Presenting IP addresses as hostnames from CSV file

ac89live
Explorer

Hello

I'm new to Splunk community and I'd like to start using Splunk as a syslog server for all traffic generated from our firewall.

We'd like to send all the logs from the firewall to the Splunk machine, using the FortiGate add-on.

 

Our firewall is sending the traffic log as source/destination IP address format, and we'd like to present it in the Splunk dashboard as hostnames. Like every IP subnet presented as a name. for example:

-- all source IPs from subnet 192.168.1.0/24 presented in Splunk dashboard as : company1_123_PO1_region1

-- all source IPs from subnet 192.168..2.0/24 presented in Splunk dashboard as : company2_321_PO2_region2

We already have a csv file which has all this information.

How can we accomplish this task?

 

Thanks

Labels (3)
0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

https://www.youtube.com/watch?v=cwEzgY0lAts&t=462s

————————————
If this helps, give a like below.

View solution in original post

thambisetty
SplunkTrust
SplunkTrust

https://www.youtube.com/watch?v=cwEzgY0lAts&t=462s

————————————
If this helps, give a like below.
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...