The HostEntries collector shows the IP addresses and host names from hosts file on Windows, Linux, and macOS devices.
Collector output
Field | Type | Description |
|---|---|---|
ipaddress | IP | An IP address set in the |
hostname | String | The host name mapping for the IP address. |
Supported versions
Windows | Linux | macOS |
|---|---|---|
3.0 and later | 3.0 and later | 3.0 and later |
Example: Find devices whose
hosts file configures access to www.malware.com.HostEntries where HostEntries hostname equals "www.malware.com"