Greetings, I am new to Splunk, but do understand most of the concepts since we use the product at work with various forwarders, etc. I am running Splunk server on a small Mini Windows 10 system with SplunkStream enabled. I am ingesting packets via a separate dedicated NIC I have setup to receive from a smart switch using port mirroring. I get plenty of useful data and SplunkStream is great, but I would like to somehow transform the inbound IP address to the host name. I only ever have one host name in the logs obviously for my Splunk host. Many of the logs I drill into and even the chart data shows the src_ip for all the host activity on my network. Appreciate any information and\or assistance to make this happen if it's possible. Hopefully I am describing the situation clearly. Thanks!
... View more