Get Public IP Add-on
Splunk Universal Forwarder and Splunk Enterprise on Windows, Linux, Unix and macOS
Collects the public IPv4 and IPv6 egress address of every Splunk Universal Forwarder and Enterprise host, on Windows, Linux, Unix and macOS.
@@shots https://cdn.prod.website-files.com/654c082e33faa8130383d311/6ac9e9e1e929bcffef02662b_gpi-1-dual-stack.webp | Splunk search showing each host's public IPv4 and IPv6 egress address, with a dual-stack Windows host highlighted ;; https://cdn.prod.website-files.com/654c082e33faa8130383d311/6ac9e9e1110c2800b7346bb9_gpi-2-map.webp | Splunk cluster map plotting where forwarders reach the internet, built from the public_ip sourcetype ;; https://cdn.prod.website-files.com/654c082e33faa8130383d311/6ac9e9e1c913829d3083bd45_gpi-3-table.webp | Splunk statistics table of host, public IP, IP version, method, provider and command ;; https://cdn.prod.website-files.com/654c082e33faa8130383d311/6ac9e9e11bc1943ca05c5fe6_gpi-4-linux.webp | Linux forwarder running get_public_ip.sh with HTTPS and DNS lookups through wget, curl, dig and nslookup ;; https://cdn.prod.website-files.com/654c082e33faa8130383d311/6ac9e9e2e929bcffef0266ce_gpi-5-windows.webp | Windows forwarder running get_public_ip.bat with DNS and HTTPS lookups through nslookup and curl @@specs Splunk versions | 9.0 to 10.6 ;; Deployment | Standalone and distributed ;; Platforms | Windows, Linux, Unix and macOS ;; CIM | 3.x to 6.x ;; Sourcetype | public_ip ;; Dependencies | None. Built-in tools only ;; Release notes | v1.1.0 on GitHub -> https://github.com/zuykn/TA-get_public_ip/releases/tag/v1.1.0
Overview
Know exactly which public IP address each Splunk Universal Forwarder and Enterprise host uses to reach the internet. The add-on collects every host's public IPv4 and IPv6 egress address on a schedule and sends it to Splunk as a searchable event.
It uses only the tools already on the host, such as curl, wget, dig, nslookup, certutil or bitsadmin, so there is nothing extra to install. It runs on Windows, Linux, Unix and macOS.
Features
- Public IPv4 and IPv6 (dual-stack) collection
- Windows, Linux, Unix and macOS, on Universal Forwarders and full Splunk instances
- HTTPS endpoint or DNS resolver lookup, with automatic fallback
- Any HTTPS endpoint that returns an IP address, or the OpenDNS and Cloudflare resolvers
- Built-in tools only, with no dependencies and a low chance of tripping EDR
- One event per run with host, public IP, IP version, method, provider and command
- Negligible CPU and memory use
Use Cases
- Map which public IPs your forwarders use to reach the internet, by host and location
- Spot hosts whose public IP changes, or that leave through an unexpected network
- Correlate firewall and perimeter logs with the hosts behind them
- Confirm IPv6 egress on dual-stack networks
Get Started
- Download the add-on from Splunkbase.
- Install it on your Universal Forwarders for collection, and on search heads for field extractions.
- Set the index and interval in inputs.conf (default 300 seconds) and enable the scripted input.
- Restart the forwarder, then search sourcetype=public_ip.
Details
Version
v1.1.0 · Oct 2025
Works with
Splunk Universal Forwarder and Splunk Enterprise on Windows, Linux, Unix and macOS
Questions or a Custom Version?
The engineers who built it can help you deploy it, tune it to your environment, or build what you need next.
Talk to Our Team →Need Help Getting It Running?
We can deploy it across your organization, tune it to your environment, or build something new around it.
Book a Call →