I have a lookup table ipn1.csv
src_ip,hostname
54.69.58.243,splunk.com
172.217.14.206,google.com
When I run:
| inputlookup "ipn1.csv"
| lookup whois host as src_ip
(lookup whois information based on the IP address) I get information populated from the whois search
When I run:
| inputlookup "ipn1.csv"
| lookup whois host as hostname
(lookup whois information based on the domain name) no information is populated.
In my use case, I want to take a domain name from a search and lookup the creation_date but I cannot seem to get results.
When doing
|whois splunk.com
it works perfectly, just not within a runtime search.
... View more