---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Playbook for OSquery of External Address in /etc/hosts file

# Playbook for OSquery of External Address in /etc/hosts file {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

This playbook provides systematic remediation steps to investigate incidents that indicate that an internal hostname or domain has been assigned to an external IP address on the local DNS(/etc/hosts) of a Linux
server.
* **[Set up the OSquery of External Address in the /etc/hosts file playbook](https://servicenow-prod.fluidtopics.net/VGsm1RftiQk_j2do4KOfww)**   
  Use the following steps to set up the OSquery of External Address in the /etc/hosts file playbook.
* **[Use the OSquery of External Address in the /etc/hosts file playbook](https://servicenow-prod.fluidtopics.net/hhyv8w6vmotWbhB58tBdrA)**   
  Use this playbook to investigate incidents that indicate that an internal hostname or domain has been assigned to an external IP address on the local DNS(/etc/hosts) of a Linux server. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the OSquery of external address in the /etc/hosts file playbook.

