All Apps and Add-ons

URL Toolbox: What is the most efficient way to map URLs with IPs to meaningful names to graph on a time chart?

caradoc
New Member

Using URL Toolbox to parse out ut_domain for varying levels of analysis - I've come up with a couple of different ways to map ut_domain to some meaningful name instead of winding up with a timechart of eight IP addresses all graphed separately with a few additional entries (google.com, apple.com, etc.), but I'm at a loss as to the most efficient way to do it. Making individual DNS queries for each unqualified IP in ut_domain is not very efficient. Placing a table of "if this is the IP in ut_domain, use this string instead for ut_domain" seems to work, but I have to think there's a better way.

Thoughts?

0 Karma

janderson19
Path Finder

You could put those IPs and their names into a lookup table. I personally don't know much about lookups buy you could try it

http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Lookup

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...