Splunk Search

Group IP addresses in CIDR format

trangadmin
New Member

Hi guys,

I am building a search where I want to report on location based on source IP address. For example within our internal network the subnet 10.0.0.0/24 corresponds to Brewton, whereas 10.1.133.0/23 also corresponds to Brewton. (I have about 23 subnets for this one location)

I have tried using this:

my search | eval subnet=case(cidrmatch("10.0.0.0/24",src)

However, it is not working at all. It will be great if you guys can give me some suggestions.

Thank you!

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

Ayn
Legend

What would be the desired result and what's the current result? Your eval statement is incomplete, so it's hard to tell from that.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...