Dashboards & Visualizations

How can I maintain a lookup table of host to IP mapping?

daniel333
Builder

All,

So there are situations where folks ask me to "check the logs on everything on subnet 1.2.3.x/25" Rather than by host. Especially with PCI.

Is there a meta data relationship stored in Splunk from the UF and the host name? What about syslog devices?

thanks in advance,
-Daniel

Tags (1)
0 Karma

ddrillic
Ultra Champion

You can potentially create additional meta-data fields with logical separation of these subnets. It can be via the beloved sourcetype field or any other field which you create.

0 Karma

Jarohnimo
Builder

Ypu Pretty much has it right search would be.

Index=UrIndex Sourcetype=whateverursourceis 1.2.3.*

This will return all the traffic back for that subnet only

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Cultivate Your Career Growth with Fresh Splunk Training

Growth doesn’t just happen—it’s nurtured. Like tending a garden, developing your Splunk skills takes the right ...

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering.  Because we’ve ...