Getting Data In

How to rename a specific IP subnets appearing in search to some name i.e city network

Explorer

index=* | stats count by sourceip,destport

I got my results against Sourceip,destport.Now i want to rename the IP's belonging to specific subnets to some specific name.

Is it possible ?

0 Karma
1 Solution

Ultra Champion

Sure.

Probably the easiest way is to put the IP subnet to name mapping in a lookup table, and then add a lookup command to your current search to map the IP address to a name. Lookups support a match_type=CIDR to enable lookups from IP to subnet.

View solution in original post

Ultra Champion

Sure.

Probably the easiest way is to put the IP subnet to name mapping in a lookup table, and then add a lookup command to your current search to map the IP address to a name. Lookups support a match_type=CIDR to enable lookups from IP to subnet.

View solution in original post