I have a lookup table of IP ranges with location names. I'm trying to search network traffic and add a "location" field to the result based on what IP range the src_ip falls under. I do not have access to any of the configuration files and would like to know if I can do this within the search.
Example of my lookup table (range_location.csv):
126.96.36.199 /21 site_1
I found a problem using CIDR that usually works in searches but it seems that doesn't match in lookups.
So a workaround is to write each address in a different row.
IP,location 10.10.10.1,site1 10.10.10.2,site1 10.10.10.3,site1 10.10.10.4,site1 10.10.10.5,site1 10.10.10.6,site2 10.10.10.7,site2 10.10.10.8,site2 10.10.10.9,site2 10.10.10.10,site2 ...
so you can use a search like this
| lookup range_location.csv range AS IP OUTPUT location
|table _time IP location