Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1694
  • Last Modified:

DNS lookup in Splunk

Hi
We are currently testing out Splunk to monitor our Cisco ASA 5510 firewall, but running into a problem. Because we are using a DHCP server on all client PCs,  just having IP address in the event data is no good. I need the source IP address in the event data for each entry to be converted to the clients name and sorted with the database.
Is this possible and how?
0
COMPSUPP
Asked:
COMPSUPP
1 Solution
 
eggm4nCommented:
Have you looked into Splunk Reverse DNS for fields?  It replaces IP addresses in specified fields with the results of a DNS lookup.  It should work with DHCP

http://splunkbase.splunk.com/apps/All/app:Splunk%20reverse%20DNS%20lookup%20for%20fields
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now