<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Match mix of CIDR Ips and IPv4 Ips from a lookup to search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Match-mix-of-CIDR-Ips-and-IPv4-Ips-from-a-lookup-to-search/m-p/533253#M150664</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/56360"&gt;@dwibedi03&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you convert all your non CIDR ips in the lookup file to add /32 to the end to make them all CIDR format.&lt;/P&gt;&lt;P&gt;In that way you can set your lookup with the advanced lookup option CIDR(Src_ip) and just do the lookup, which will find it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Dec 2020 23:03:31 GMT</pubDate>
    <dc:creator>bowesmana</dc:creator>
    <dc:date>2020-12-15T23:03:31Z</dc:date>
    <item>
      <title>Match mix of CIDR Ips and IPv4 Ips from a lookup to search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Match-mix-of-CIDR-Ips-and-IPv4-Ips-from-a-lookup-to-search/m-p/533193#M150653</link>
      <description>&lt;P&gt;I have a lookup table which consists of src_ip. This source Ip has mix of Ips in the format:&lt;/P&gt;&lt;TABLE width="64"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Src_ip&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64"&gt;163.74.7.212&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;163.74.13.57&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;67.75.175.32/27&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;68.143.151.125/26&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to match this lookup table to my search which consists of the field src_ip in my data. But how do i do that since it is a mix of cidr and normal ips? My actual data for src_ip doesnt consits of cidr ips. Can someone let me know ?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 16:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Match-mix-of-CIDR-Ips-and-IPv4-Ips-from-a-lookup-to-search/m-p/533193#M150653</guid>
      <dc:creator>dwibedi03</dc:creator>
      <dc:date>2020-12-15T16:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Match mix of CIDR Ips and IPv4 Ips from a lookup to search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Match-mix-of-CIDR-Ips-and-IPv4-Ips-from-a-lookup-to-search/m-p/533253#M150664</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/56360"&gt;@dwibedi03&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you convert all your non CIDR ips in the lookup file to add /32 to the end to make them all CIDR format.&lt;/P&gt;&lt;P&gt;In that way you can set your lookup with the advanced lookup option CIDR(Src_ip) and just do the lookup, which will find it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 23:03:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Match-mix-of-CIDR-Ips-and-IPv4-Ips-from-a-lookup-to-search/m-p/533253#M150664</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2020-12-15T23:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Match mix of CIDR Ips and IPv4 Ips from a lookup to search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Match-mix-of-CIDR-Ips-and-IPv4-Ips-from-a-lookup-to-search/m-p/533331#M150690</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;: I thought of doing that but I didn't know how to use the lookup after that. Can you explain me in detail about the advanced lookup option?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 13:52:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Match-mix-of-CIDR-Ips-and-IPv4-Ips-from-a-lookup-to-search/m-p/533331#M150690</guid>
      <dc:creator>dwibedi03</dc:creator>
      <dc:date>2020-12-16T13:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: Match mix of CIDR Ips and IPv4 Ips from a lookup to search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Match-mix-of-CIDR-Ips-and-IPv4-Ips-from-a-lookup-to-search/m-p/533394#M150711</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/56360"&gt;@dwibedi03&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have a lookup file, says ips.csv and then you create a lookup definition (which is an abstraction layer on top of the lookup file). Connect it to the actual file itself and then set the Src_ip field to be a CIDR type field like this&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bowesmana_0-1608175537749.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12310i49F1ABF4AAA6C574/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bowesmana_0-1608175537749.png" alt="bowesmana_0-1608175537749.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;then just use the lookup definition in the lookup command, not the file itself, so&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;base search
| lookup ips Src_ip as src_ip output Src_ip as ipFound
...&lt;/LI-CODE&gt;&lt;P&gt;so this assumes your event field is src_ip and the CSV file has a column called Src_ip. After this executes, you will have a new field ipFound if the IP exists in the CIDR range of one of the ranges, or null if not.&lt;/P&gt;&lt;P&gt;You can then do this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where isnull(ipFound)&lt;/LI-CODE&gt;&lt;P&gt;to see if it was NOT found&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 03:29:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Match-mix-of-CIDR-Ips-and-IPv4-Ips-from-a-lookup-to-search/m-p/533394#M150711</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2020-12-17T03:29:26Z</dc:date>
    </item>
  </channel>
</rss>

