WhoisXML Registrant Alert API is an application for Splunk. It is ideal for monitoring specific domain registrants to be alerted whenever their information is linked to a newly-registered or just-expired domain name within Splunk.
Prerequisites
You need to have Splunk Enterprise installed and configured. To do so, please refer to the official documentation.
Configuring the extension
1. Log in to Splunk.
2. Download and install the application. This can be done from within Splunk. (https://splunkbase.splunk.com/app/5236)
3. You can start configuring immediately once the application is installed.
3.1 You can also configure the application on the Apps page. Click on Set up next to the application name.
4. Fill in your API key and click on Save.
Using the extension
1. On the Registrant Alert lookup page you can perform instant Registrant Alert lookups.
2. To integrate Registrant Alert splunk up into your script you can use the command wxaregalert. It takes up to 18 arguments: term1-term4, where you can provide the search terms, api_key (optional), where you can provide your API key, exclude_term1 – exclude_term4, which is used to specify exclude terms to filter results, advanced_term1 – advanced_term4 and advanced_field1 – advanced_field4 where you can specify advanced search terms. Please visit API documentation page to get further information.