Hi there,
We are migrating from Kiwi syslog and one of the things Kiwi can do is show hostnames instead of IP addresses in the events.
So what I want is when I search for a host or search against an ACL rule, is that it (if it can resolve the hostname) will show the hostname instead of the IP address.
I'm wondering if anyone has managed to get this working at all?
Cheers.
Do you have a list of ip addresses and their hostnames?
If yes then you can add this list as lookup and automate the lookup to get the hostnames at search time
Reference:
http://docs.splunk.com/Documentation/Splunk/7.0.2/Knowledge/DefineanautomaticlookupinSplunkWeb
Let me know if this helps!!
Hi, thanks for your response!
This looks interesting I will give it a shot.
So there is no way for it query the DNS server instead of using a csv file?
any sample data of what you want AND how your logs look like?
Below is what I currently see (edited out ip addresses).
Link:
What I would like to see is hostnames instead of IP addresses.