Splunk Search
Highlighted

Splunk DNS Resolution: How to get IPs resolve to host names?

New Member

Hello all.

I am trying to complete something that should be easy. I wish to have IPs resolve to host names in the Splunk command.
I have read the posts and the Splunk help on this, but nothing appears to be working properly with this. Accordingly,
Can anyone provide a valid and exact step-by-step for this, and do not point to the docs?

0 Karma
Highlighted

Re: Splunk DNS Resolution: How to get IPs resolve to host names?

Esteemed Legend

Like this:

... | lookup dnslookup clientip as host | table host,clienthost
0 Karma
Highlighted

Re: Splunk DNS Resolution: How to get IPs resolve to host names?

Do you mean:

... | lookup dnslookup clientip as host | table host,clientip

0 Karma
Highlighted

Re: Splunk DNS Resolution: How to get IPs resolve to host names?

Esteemed Legend

No, because the lookup creates the field clienthost and furthermore, clientip does not exist (except inside of the lookup table).