Splunk Search

Can both hostname and source IP be searchable?

yumology
Path Finder

Right now we have a lot of devices reporting syslogs into splunk. I'd really like to be able to search them by hostname or IP address. Is there a way to get both the IP address and the DNS lookup of the device into Splunk for the same syslog message?

For instance if I have a device located at 172.16.57.1 and it's in DNS as YUM-CA-FW, then it would be nice to search for this device either way:
host_ip="172.16.57.1"
or
host_name="YUM-CA-FW"

Is this possible?

If it is, can I take it a step further and have both a host_realIP and host_natIP?

Tags (2)
1 Solution

IgorB
Path Finder
0 Karma

Horor
New Member

Hi,
you can Get both Ip-Address and Host using the site Ip-Details.com .They are accurate and Reliable.I usually do Ip-Search in this site.So I Prefer you to this site.It will be more Useful to you....

0 Karma

IgorB
Path Finder

You can easily do it by using lookups.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...