index=* | stats count by sourceip,destport
I got my results against Sourceip,destport.Now i want to rename the IP's belonging to specific subnets to some specific name.
Is it possible ?
Probably the easiest way is to put the IP subnet to name mapping in a lookup table, and then add a lookup command to your current search to map the IP address to a name. Lookups support a match_type=CIDR to enable lookups from IP to subnet.
View solution in original post