Whois XML IP Netblocks API is an application for Splunk. It provides detailed IP range info that a particular IP address belongs to within Splunk.
Prerequisites
You need to have Splunk Enterprise installed and configured. To do so, please refer to the official documentation.
Configuring the extension
1. Log in to Splunk.
2. Download and install the application. This can be done from within Splunk. (https://splunkbase.splunk.com/app/5371)
3. You can start configuring immediately once the application is installed.
3.1 You can also configure the application on the Apps page. Click on Set up next to the application name.
4. Fill in your API key and click on Save.
Using the extension
1. On the IP Netblocks lookup page you can perform instant searches.
2. To integrate IP Netblocks API into your script you can use the wxaipnetblocks command. It takes 4 arguments: search_terms providing IP/ASN/comma-separated terms (netname, description, remarks or organization) to search for depending on term_type (ip/asn/org), mask (optional for IP) letting you get ranges by CIDR and api_key (optional) taken from config if not specified.