Splunk Search

How to implement whois lookup for ips hitting fw?

balu1211
Path Finder

Hi..

I have to find the ip address hitting fw for that i have to implement the whois lookup for the hitting ips but no use i tried with the app Whois it's not working.

Is there any way

 

Thanks....

 

 

Labels (1)
0 Karma

starcher
Influencer

You could write your own external lookup. You’ll have to read docs and be ok with python. The bigger issue is any free whois service won’t let you mass spam lookup and it will be slow. 

so it is more important to decide what your search is trying to answer. Boil down to a small final result set before running whois lookups. 

0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...