Splunk Search

DNS Names in Events

FraserC1
Path Finder

Hi there,

We are migrating from Kiwi syslog and one of the things Kiwi can do is show hostnames instead of IP addresses in the events.

So what I want is when I search for a host or search against an ACL rule, is that it (if it can resolve the hostname) will show the hostname instead of the IP address.
I'm wondering if anyone has managed to get this working at all?

Cheers.

0 Karma

deepashri_123
Motivator

Do you have a list of ip addresses and their hostnames?
If yes then you can add this list as lookup and automate the lookup to get the hostnames at search time
Reference:
http://docs.splunk.com/Documentation/Splunk/7.0.2/Knowledge/DefineanautomaticlookupinSplunkWeb

Let me know if this helps!!

0 Karma

FraserC1
Path Finder

Hi, thanks for your response!
This looks interesting I will give it a shot.
So there is no way for it query the DNS server instead of using a csv file?

0 Karma

Sukisen1981
Champion

any sample data of what you want AND how your logs look like?

0 Karma

FraserC1
Path Finder

Below is what I currently see (edited out ip addresses).

Link: alt text

What I would like to see is hostnames instead of IP addresses.

0 Karma
Get Updates on the Splunk Community!

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...