Splunk Search

Group IP addresses in CIDR format

trangadmin
New Member

Hi guys,

I am building a search where I want to report on location based on source IP address. For example within our internal network the subnet 10.0.0.0/24 corresponds to Brewton, whereas 10.1.133.0/23 also corresponds to Brewton. (I have about 23 subnets for this one location)

I have tried using this:

my search | eval subnet=case(cidrmatch("10.0.0.0/24",src)

However, it is not working at all. It will be great if you guys can give me some suggestions.

Thank you!

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

Ayn
Legend

What would be the desired result and what's the current result? Your eval statement is incomplete, so it's hard to tell from that.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...