WhoIsLookup
StandardThe WhoIsLookup application enables you to use the whoislookup process command to enrich logs with the information related to the given field from the WHOIS database. The WHOIS database consists of information about the registered users of an Internet resource such as registrar, IP address, registry expiry date, updated date, name server information, and other information. If the specified field name and its corresponding value are matched with the equivalent field values of the WHOIS database, the process command enriches the search result.
Release Details
Installation
Follow these steps to install the WhoIsLookup v3.0.0:
- Download the WhoIsLookup_3.0.0.zip file provided above in the Download section.
- Extract the zip file to obtain the WhoIsLookup_3.0.0.pak file.
- Install the plugin by importing the pak file to LogPoint under Settings >> System >> Applications.
Past Release
For LogPoint v6.7 or later ▾
Bug Fix
Usage Information
Syntax: | process whoislookup(field_name)
For example, "| process whoislookup(domain)" command enriches the log message with values associated with the matched domain field from the WHOIS database.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.
The package is announced with version number 5.0.0, but the download package is called WhoIsLookup_4.0.0.pak. Which version is correct?
@Hans, The correct version is 4.0.0. But, can you please let me know where it was announced as 5.0.0?
Hi Manjul,
please take a look at https://servicedesk.logpoint.com/hc/en-us/sections/115001170305-Applications-LP-6-#W
Thanks Hans, We are in talks with Service Center support to fix the issues in Help Center. The versioning issue is fixed as of now.
Another mismatch.
At "For LogPoint v6.7 or later" is written:
Supported On: LogPoint v6.6.0 or later