Splunk Search

Splunk DNS Resolution: How to get IPs resolve to host names?

New Member

Hello all.

I am trying to complete something that should be easy. I wish to have IPs resolve to host names in the Splunk command.
I have read the posts and the Splunk help on this, but nothing appears to be working properly with this. Accordingly,
Can anyone provide a valid and exact step-by-step for this, and do not point to the docs?

0 Karma

Esteemed Legend

Like this:

... | lookup dnslookup clientip as host | table host,clienthost
0 Karma


Do you mean:

... | lookup dnslookup clientip as host | table host,clientip

0 Karma

Esteemed Legend

No, because the lookup creates the field clienthost and furthermore, clientip does not exist (except inside of the lookup table).

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...