Dashboards & Visualizations

How can I maintain a lookup table of host to IP mapping?

daniel333
Builder

All,

So there are situations where folks ask me to "check the logs on everything on subnet 1.2.3.x/25" Rather than by host. Especially with PCI.

Is there a meta data relationship stored in Splunk from the UF and the host name? What about syslog devices?

thanks in advance,
-Daniel

Tags (1)
0 Karma

ddrillic
Ultra Champion

You can potentially create additional meta-data fields with logical separation of these subnets. It can be via the beloved sourcetype field or any other field which you create.

0 Karma

Jarohnimo
Builder

Ypu Pretty much has it right search would be.

Index=UrIndex Sourcetype=whateverursourceis 1.2.3.*

This will return all the traffic back for that subnet only

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...