Hello all.
I am trying to complete something that should be easy. I wish to have IPs resolve to host names in the Splunk command.
I have read the posts and the Splunk help on this, but nothing appears to be working properly with this. Accordingly,
Can anyone provide a valid and exact step-by-step for this, and do not point to the docs?
Like this:
... | lookup dnslookup clientip as host | table host,clienthost
Do you mean:
... | lookup dnslookup clientip as host | table host,clientip
No, because the lookup
creates the field clienthost
and furthermore, clientip
does not exist (except inside of the lookup table).