I am trying to complete something that should be easy. I wish to have IPs resolve to host names in the Splunk command.
I have read the posts and the Splunk help on this, but nothing appears to be working properly with this. Accordingly,
Can anyone provide a valid and exact step-by-step for this, and do not point to the docs?
No, because the
lookup creates the field
clienthost and furthermore,
clientip does not exist (except inside of the lookup table).