Splunk Search

Some hosts come in as IP some as hostname easy way to make searching easier?

Pierceyuk
Path Finder

Hey, So we have a few hundred hosts coming in, some come in as dns hostname, some come in as IP address.

What is the best practice for dealing with this? Make everything IP or hostname?

Is it possible to add an IP and hostname to all these records via some lookup? Or should I 'decide' on either hostnames or IP addresses and try to get everything set the same?

Thanks,
Pierce

Tags (3)
0 Karma
1 Solution

somesoni2
Revered Legend

Best approach will be have your forwarder configured to send in one format. If its not easy, then you can use dns lookup feature in splunk to convert all to one type, either hostname or IP, up to you. For reference see this: http://answers.splunk.com/answers/8051/dns-lookup-via-splunk

View solution in original post

somesoni2
Revered Legend

Best approach will be have your forwarder configured to send in one format. If its not easy, then you can use dns lookup feature in splunk to convert all to one type, either hostname or IP, up to you. For reference see this: http://answers.splunk.com/answers/8051/dns-lookup-via-splunk

Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...