Splunk Enterprise

How to get the ip address of specific host ?

_Raj
Engager

How to get the ip address of specific host ?

Labels (1)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @_Raj,

You can use dnslookup like below. It will ask to DNS for IP resolution and create a new field as host_ip

| lookup dnslookup clienthost as host OUTPUT clientip as host_ip

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

splunkreal
Motivator

Works fine, thanks!

* If this helps, please upvote or accept solution if it solved *
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @_Raj,

You can use dnslookup like below. It will ask to DNS for IP resolution and create a new field as host_ip

| lookup dnslookup clienthost as host OUTPUT clientip as host_ip

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...