Splunk Search

DNS Names in Events

FraserC1
Path Finder

Hi there,

We are migrating from Kiwi syslog and one of the things Kiwi can do is show hostnames instead of IP addresses in the events.

So what I want is when I search for a host or search against an ACL rule, is that it (if it can resolve the hostname) will show the hostname instead of the IP address.
I'm wondering if anyone has managed to get this working at all?

Cheers.

0 Karma

deepashri_123
Motivator

Do you have a list of ip addresses and their hostnames?
If yes then you can add this list as lookup and automate the lookup to get the hostnames at search time
Reference:
http://docs.splunk.com/Documentation/Splunk/7.0.2/Knowledge/DefineanautomaticlookupinSplunkWeb

Let me know if this helps!!

0 Karma

FraserC1
Path Finder

Hi, thanks for your response!
This looks interesting I will give it a shot.
So there is no way for it query the DNS server instead of using a csv file?

0 Karma

Sukisen1981
Champion

any sample data of what you want AND how your logs look like?

0 Karma

FraserC1
Path Finder

Below is what I currently see (edited out ip addresses).

Link: alt text

What I would like to see is hostnames instead of IP addresses.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...