• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1738
  • Last Modified:

DNS lookup in Splunk

Hi
We are currently testing out Splunk to monitor our Cisco ASA 5510 firewall, but running into a problem. Because we are using a DHCP server on all client PCs,  just having IP address in the event data is no good. I need the source IP address in the event data for each entry to be converted to the clients name and sorted with the database.
Is this possible and how?
0
COMPSUPP
Asked:
COMPSUPP
1 Solution
 
eggm4nCommented:
Have you looked into Splunk Reverse DNS for fields?  It replaces IP addresses in specified fields with the results of a DNS lookup.  It should work with DHCP

http://splunkbase.splunk.com/apps/All/app:Splunk%20reverse%20DNS%20lookup%20for%20fields
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Protect Your Employees from Wi-Fi Threats

As Wi-Fi growth and popularity continues to climb, not everyone understands the risks that come with connecting to public Wi-Fi or even offering Wi-Fi to employees, visitors and guests. Download the resource kit to make sure your safe wherever business takes you!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now