Splunk Search

How to find out one of the host of ip adresses?

phanichintha
Path Finder

what is the command to find out one of the host name of Ip adress.

Tags (1)

FrankVl
Ultra Champion

Splunk has a built in 'external lookup' called dnslookup that you can use (assuming the address you want to lookup is in a field called ipAddress): | lookup dnslookup clientip as ipAddress

See also: https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/DefineanexternallookupinSplunkWeb#Exte...

0 Karma

jawaharas
Motivator
  1. Install the 'dnslookup' app - https://splunkbase.splunk.com/app/1535/
  2. Get host name of ip using below command

| dnslookup reverse ip host

0 Karma

FrankVl
Ultra Champion

No need to install a 6y old app for that. This functionality is built in nowadays 🙂

0 Karma

jawaharas
Motivator

Thanks. This also works.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!