Splunk Search

Group IP addresses in CIDR format

New Member

Hi guys,

I am building a search where I want to report on location based on source IP address. For example within our internal network the subnet 10.0.0.0/24 corresponds to Brewton, whereas 10.1.133.0/23 also corresponds to Brewton. (I have about 23 subnets for this one location)

I have tried using this:

my search | eval subnet=case(cidrmatch("10.0.0.0/24",src)

However, it is not working at all. It will be great if you guys can give me some suggestions.

Thank you!

Tags (1)
0 Karma

Splunk Employee
Splunk Employee

Legend

What would be the desired result and what's the current result? Your eval statement is incomplete, so it's hard to tell from that.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!