Splunk Query for adding a column for ISP of blocked IP address?
Thank you,
Yes, I want to find the organization/ ISP of the IP addresses I have on my table. Yes I can create a mapping on my splunk server.
I'm trying to include in my query of IP address that I have listed on a table to also display the ISP/ Organization of the IP addresses.
Perhaps the easiest way to do that is by using a lookup table. You will need to put your ISP mapping data into a CSV file so it looks something like this.
Address, ISP
1.2.0.0/16, xyz.net
2.3.0.0/16, wxy.net
Create a lookup definition (Settings->Lookups->Lookup Definitions) that references this file. In the "Match type" field enter "CIDR(Address)".
In your search query, add the lookup command to map address to ISP.
<your search> | lookup ISPs address as ip_address OUTPUT ISP
| table ip_address, ISP