Dashboards & Visualizations

How can I maintain a lookup table of host to IP mapping?

daniel333
Builder

All,

So there are situations where folks ask me to "check the logs on everything on subnet 1.2.3.x/25" Rather than by host. Especially with PCI.

Is there a meta data relationship stored in Splunk from the UF and the host name? What about syslog devices?

thanks in advance,
-Daniel

Tags (1)
0 Karma

ddrillic
Ultra Champion

You can potentially create additional meta-data fields with logical separation of these subnets. It can be via the beloved sourcetype field or any other field which you create.

0 Karma

Jarohnimo
Builder

Ypu Pretty much has it right search would be.

Index=UrIndex Sourcetype=whateverursourceis 1.2.3.*

This will return all the traffic back for that subnet only

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...