Splunk Search

How to implement whois lookup for ips hitting fw?

balu1211
Path Finder

Hi..

I have to find the ip address hitting fw for that i have to implement the whois lookup for the hitting ips but no use i tried with the app Whois it's not working.

Is there any way

 

Thanks....

 

 

Labels (1)
0 Karma

starcher
Influencer

You could write your own external lookup. You’ll have to read docs and be ok with python. The bigger issue is any free whois service won’t let you mass spam lookup and it will be slow. 

so it is more important to decide what your search is trying to answer. Boil down to a small final result set before running whois lookups. 

0 Karma
Get Updates on the Splunk Community!

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

AI Adoption Hub Launch | Curated Resources to Get Started with AI in Splunk

Hey Splunk Practitioners and AI Enthusiasts! It’s no secret (or surprise) that AI is at the forefront of ...