Domain Reputation API Splunk application tutorial Domain Reputation API Splunk application tutorial

WhoisXML Domain Reputation API is an application for Splunk. It lets you audit domain names/IP addresses and assign risk scores based on their content, configuration, infrastructure etc. within Splunk.

Prerequisites

You need to have Splunk Enterprise installed and configured. To do so, please refer to the official documentation.

Configuring the extension

1. Log in to Splunk.

Log in to Splunk.

2. Download and install the application. This can be done from within Splunk. (https://splunkbase.splunk.com/app/5401)

3. You can start configuring immediately once the application is installed.

You can start configuring immediately once the application is installed.

3.1 You can also configure the application on the Apps page. Click on Set up next to the application name.

You can also configure the application on the Apps page. Click Set up near the application name.

4. Fill in your API key and click on Save.

Fill in your API key and click on Save.

Using the extension

1. On the Domain Reputation lookup page you can perform instant searches.

On the Domain Reputation lookup page you can perform instant searches.

2. To integrate Domain Reputation lookup into your script you can use the wxadomainrep command. It takes 3 arguments: search_term providing comma-separated domain names or IP addresses, mode (optional, fast/full, default “fast”) specifying the test approach with “fast” skipping some heavy checks and costing 1 credit instead of 3 and api_key (optional) taken from config if not specified.

Integrate Domain Reputation lookup.