Splunk Search

How to implement whois lookup for ips hitting fw?

balu1211
Path Finder

Hi..

I have to find the ip address hitting fw for that i have to implement the whois lookup for the hitting ips but no use i tried with the app Whois it's not working.

Is there any way

 

Thanks....

 

 

Labels (1)
0 Karma

starcher
Influencer

You could write your own external lookup. You’ll have to read docs and be ok with python. The bigger issue is any free whois service won’t let you mass spam lookup and it will be slow. 

so it is more important to decide what your search is trying to answer. Boil down to a small final result set before running whois lookups. 

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...