Dashboards & Visualizations

How can I maintain a lookup table of host to IP mapping?

daniel333
Builder

All,

So there are situations where folks ask me to "check the logs on everything on subnet 1.2.3.x/25" Rather than by host. Especially with PCI.

Is there a meta data relationship stored in Splunk from the UF and the host name? What about syslog devices?

thanks in advance,
-Daniel

Tags (1)
0 Karma

ddrillic
Ultra Champion

You can potentially create additional meta-data fields with logical separation of these subnets. It can be via the beloved sourcetype field or any other field which you create.

0 Karma

Jarohnimo
Builder

Ypu Pretty much has it right search would be.

Index=UrIndex Sourcetype=whateverursourceis 1.2.3.*

This will return all the traffic back for that subnet only

0 Karma
Get Updates on the Splunk Community!

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...