DNS Lookup API Splunk application tutorial DNS Lookup API Splunk application tutorial

Whois XML DNS Lookup API is an application for Splunk. It lets you check DNS records within Splunk.

Prerequisites

You need to have Splunk Enterprise installed and configured. To do so, please refer to the official documentation.

Configuring the extension

1. Log in to Splunk.

Log in to Splunk.

2. Download and install the application. This can be done from within Splunk. (https://splunkbase.splunk.com/app/5342)

3. You can start configuring immediately once the application is installed.

You can start configuring immediately once the application is installed.

3.1 You can also configure the application on the Apps page. Click on Set up next to the application name.

You can also configure the application on the Apps page. Click Set up near the application name.

4. Fill in your API key and click on Save.

Fill in your API key and click on Save.

Using the extension

1. On the DNS Lookup page you can perform lookups.

On the DNS Lookup page you can perform instant lookups.

2. To integrate Website Contacts lookup into your script you can use the command wxadnslookup. It takes 3 arguments: search_term, where you provide a domain name, record_types where you can specify required DNS records, api_key (optional), where you can provide your API key, otherwise it will be taken from a config file. You can find all supported DNS types on the documentation page. Please note that the ‘record_fields’ and the ‘values’ columns are arrays. The values[x] contains values of the DNS record field, which name is stored in record_fields[x].

Integrate DNS Lookup.