Splunk Search

Can I return the host IP address in WinEventLog metadata search?

lball
Explorer

I'm trying to use a metadata search to quickly return the hosts that are currently sending logs to Splunk to determine if we are missing any logs. Here is the current search:

| metadata type=hosts index=wineventlog | table host

Is there a way to also return the IP address of the host from the metadata search?

0 Karma

Vijeta
Influencer

Use this-

| metadata type=hosts index=wineventlog | table host| lookup dnslookup clienthost AS host

Also this documentation will be helpful
http://docs.splunk.com/Documentation/Splunk/6.2.1/Knowledge/Addfieldsfromexternaldatasources#Externa...

0 Karma

lball
Explorer

I tried this search string, but I got an empty clientip field added to the table...not exactly why it's not returning the IP values. No error is shown...

0 Karma

dyeo
Engager

same for me... the clientip field is empty

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...

Major Splunk Upgrade – Prepare your Environment for Splunk 10 Now!

Attention App Developers: Test Your Apps with the Splunk 10.0 Beta and Ensure Compatibility Before the ...

Stay Connected: Your Guide to June Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...