Reverse WHOIS API Splunk application tutorial | Platforms | Reverse WHOIS API | WhoisXML API

Reverse WHOIS API Splunk application tutorial Reverse WHOIS API Splunk application tutorial

Whois XML Reverse API is an application for Splunk. It allows gathering list of domain names which contain a specified search term in their whois records within Splunk.

Prerequisites

You need to have Splunk Enterprise installed and configured. To do so, please refer to the official documentation.

Configuring the extension

1. Log in to Splunk.

Log in to Splunk.

2. Download and install the application. This can be done from within Splunk. (https://splunkbase.splunk.com/app/5079)

Download and install the application. This can be done from within Splunk.

3. You can start configuring immediately once the application is installed.

You can start configuring immediately once the application is installed.

3.1 You can also configure the application on the Apps page. Click on Set up next to the application name.

You can also configure the application on the Apps page. Click Set up near the application name.

4. Fill in your API key and click on Save.

Fill in your API key and click on Save.

Using the extension

1. On the Reverse WHOIS lookup page you can perform instant Reverse WHOIS lookups.

On the WHOIS lookup page you can perform instant WHOIS lookups.

2. To integrate Reverse WHOIS lookup into your script you can use the command wxareversewhois. It takes 3 arguments: include_term, where you provide the search term, api_key (optional), where you can provide your API key, otherwise it will be taken from a config file, and search_type (optional), which could current or historic.

Integrate Reverse WHOIS lookup.