Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

WhoIsLookup

Standard

The WhoIsLookup application enables you to use the whoislookup process command to enrich logs with the information related to the given field from the WHOIS database. The WHOIS database consists of information about the registered users of an Internet resource such as registrar, IP address, registry expiry date, updated date, name server information, and other information. If the specified field name and its corresponding value are matched with the equivalent field values of the WHOIS database, the process command enriches the search result.

Release Details

Version: 3.0.0
Release date: 2018-07-30
Supported On: LogPoint v6.3.0 and later
SHA 256: bc5e8a1e4dfcf8348be480a773b116b7ae8b0eea6bed4182c547e36ccdeed3d7
Download

Installation

Follow these steps to install the WhoIsLookup v3.0.0:

  1. Download the WhoIsLookup_3.0.0.zip file provided above in the Download section.
  2. Extract the zip file to obtain the WhoIsLookup_3.0.0.pak file.
  3. Install the plugin by importing the pak file to LogPoint under Settings >> System >> Applications.

Past Release

For LogPoint v6.7 or later ▾
Version: 4.0.0
Release date: 2020-02-26
Supported On: LogPoint v6.6.0 or later
SHA 256: d420fd71dfec3e68ec90467c0eec15895311b6d0ca6d2644bb1237eb378120d5
Download

Bug Fix

Previously, while using the process command, if the outgoing traffic was blocked, the search became unresponsive. The issue has now been resolved.

Usage Information

Syntax: | process whoislookup(field_name)

For example, "| process whoislookup(domain)" command enriches the log message with values associated with the matched domain field from the WHOIS database. 

Support

If you have any questions or require assistance, create a support ticket.

Comments

  • Avatar
    Hans Vedder
    February 27, 2020 07:36

    The package is announced with version number 5.0.0, but the download package is called WhoIsLookup_4.0.0.pak. Which version is correct?

    Comment actions Permalink
  • Avatar
    Manjul Bhattarai
    February 27, 2020 07:40

    @Hans, The correct version is 4.0.0. But, can you please let me know where it was announced as 5.0.0?

    Comment actions Permalink
  • Avatar
    Hans Vedder
    February 27, 2020 07:43

    Hi Manjul,

    please take a look at https://servicedesk.logpoint.com/hc/en-us/sections/115001170305-Applications-LP-6-#W

    Comment actions Permalink
  • Avatar
    Manjul Bhattarai
    February 27, 2020 07:51

    Thanks Hans, We are in talks with Service Center support to fix the issues in Help Center. The versioning issue is fixed as of now.

    Comment actions Permalink
  • Avatar
    Hans Vedder
    February 27, 2020 07:56

    Another mismatch.

    At "For LogPoint v6.7 or later" is written:

    Supported On: LogPoint v6.6.0 or later

    Comment actions Permalink

Article is closed for comments.

Follow

Related articles

  • Windows
  • Lookup
  • Universal Normalizer
  • ChatGPT Integration
  • Evaluation Process Plugin
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.