Splunk Search

Can I return the host IP address in WinEventLog metadata search?

lball
Explorer

I'm trying to use a metadata search to quickly return the hosts that are currently sending logs to Splunk to determine if we are missing any logs. Here is the current search:

| metadata type=hosts index=wineventlog | table host

Is there a way to also return the IP address of the host from the metadata search?

0 Karma

Vijeta
Influencer

Use this-

| metadata type=hosts index=wineventlog | table host| lookup dnslookup clienthost AS host

Also this documentation will be helpful
http://docs.splunk.com/Documentation/Splunk/6.2.1/Knowledge/Addfieldsfromexternaldatasources#Externa...

0 Karma

lball
Explorer

I tried this search string, but I got an empty clientip field added to the table...not exactly why it's not returning the IP values. No error is shown...

0 Karma

dyeo
Engager

same for me... the clientip field is empty

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...