Splunk Search

Can both hostname and source IP be searchable?

yumology
Path Finder

Right now we have a lot of devices reporting syslogs into splunk. I'd really like to be able to search them by hostname or IP address. Is there a way to get both the IP address and the DNS lookup of the device into Splunk for the same syslog message?

For instance if I have a device located at 172.16.57.1 and it's in DNS as YUM-CA-FW, then it would be nice to search for this device either way:
host_ip="172.16.57.1"
or
host_name="YUM-CA-FW"

Is this possible?

If it is, can I take it a step further and have both a host_realIP and host_natIP?

Tags (2)
1 Solution

IgorB
Path Finder
0 Karma

Horor
New Member

Hi,
you can Get both Ip-Address and Host using the site Ip-Details.com .They are accurate and Reliable.I usually do Ip-Search in this site.So I Prefer you to this site.It will be more Useful to you....

0 Karma

IgorB
Path Finder

You can easily do it by using lookups.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...