Splunk today is IPv4 subnet aware so that if you do a search with something like ip_address = 10.0.0.0/24 .. splunk knows to look for items 10.0.0.0 thru 10.0.0.255 ... NICE !
Now what about IPV6 ... I think the answer is No. my question is when or how can this be done
example IPv6_ADDR = 2001:54FF::/48 would look for a whole lot of stuff but something like
2001:54FF:: to 2001:54FF:0000:FFFF:FFFF
And this gets instresting as you can show the first part of the IPV6 address as
It depends on what the system sending the log spits out ...