Splunk Search

Help With RDNS For scr_ip in Syslog Message

tbrichards
New Member

I am trying to display the fqdn instead of the IP address for the internal host in a syslog message. In the example below, I would like to resolve the 10.10.10.100 address to FQDN and display that in Splunk, instead of the IP address.

Any assistance would be greatly appreciated.

Jul 31 01:46:08 [10.10.10.1] Jul 31 2012 01:46:08 EXT-FW : %ASA-4-338008: Dynamic Filter dropped blacklisted TCP traffic from inside:10.10.10.100/54749 (100.100.100.100/57315) to outside:69.63.190.74/80 (69.63.190.74/80), destination 69.63.190.74 resolved from dynamic list: 69.63.190.74/255.255.255.255, threat-level: very-high, category: Malware
Tags (1)
0 Karma

sdvorak_splunk
Splunk Employee
Splunk Employee
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...