← All Apps
Get Public IP Add-on icon

Get Public IP Add-on

Splunk Universal Forwarder and Splunk Enterprise on Windows, Linux, Unix and macOS

Collects the public IPv4 and IPv6 egress address of every Splunk Universal Forwarder and Enterprise host, on Windows, Linux, Unix and macOS.

Download on Splunkbase ↗Get Help Setting It Up

Overview

Know exactly which public IP address each Splunk Universal Forwarder and Enterprise host uses to reach the internet. The add-on collects every host's public IPv4 and IPv6 egress address on a schedule and sends it to Splunk as a searchable event.

It uses only the tools already on the host, such as curl, wget, dig, nslookup, certutil or bitsadmin, so there is nothing extra to install. It runs on Windows, Linux, Unix and macOS.

Features

  • Public IPv4 and IPv6 (dual-stack) collection
  • Windows, Linux, Unix and macOS, on Universal Forwarders and full Splunk instances
  • HTTPS endpoint or DNS resolver lookup, with automatic fallback
  • Any HTTPS endpoint that returns an IP address, or the OpenDNS and Cloudflare resolvers
  • Built-in tools only, with no dependencies and a low chance of tripping EDR
  • One event per run with host, public IP, IP version, method, provider and command
  • Negligible CPU and memory use

Use Cases

  • Map which public IPs your forwarders use to reach the internet, by host and location
  • Spot hosts whose public IP changes, or that leave through an unexpected network
  • Correlate firewall and perimeter logs with the hosts behind them
  • Confirm IPv6 egress on dual-stack networks

Get Started

  1. Download the add-on from Splunkbase.
  2. Install it on your Universal Forwarders for collection, and on search heads for field extractions.
  3. Set the index and interval in inputs.conf (default 300 seconds) and enable the scripted input.
  4. Restart the forwarder, then search sourcetype=public_ip.
← Back to All Apps

Details

Version

v1.1.0 · Oct 2025

Works with

Splunk Universal Forwarder and Splunk Enterprise on Windows, Linux, Unix and macOS

Questions or a Custom Version?

The engineers who built it can help you deploy it, tune it to your environment, or build what you need next.

Talk to Our Team →

Need Help Getting It Running?

We can deploy it across your organization, tune it to your environment, or build something new around it.

Book a Call →