Splunk Search

How to Join IP with CIDR?

kiran331
Builder

Hi

I'm trying to Compare the IP with CIDR Lookup to get the result.In the Lookup i got the CIDR range, City, manager.

Data in lookup:

IP Country Manager
10.21.22.23/24 US abc

Search I'm using:

index=.....|table dest_ip|join type=left dest_ip[|inputlookup range.csv|rename IP as dest_ip]|table dest_ip city Manager

Tags (2)
0 Karma

sundareshr
Legend

Look at this answer. Setup match_type = CIDR(IP) in the transforms for your lookup file

https://answers.splunk.com/answers/5916/using-cidr-in-a-lookup-table.html

0 Karma

kiran331
Builder

Thanks for the response! I added this to transforms.conf.
[range]
filename = range.csv
max_matches = 1
min_matches = 1
default_match = OK
match_type = CIDR(IP)

But when i try to search, its showing errors.

search:
index=...|lookup range IP as dest_Ip OUTPUT Manager|table dest_ip Manager

0 Karma

niddhi
Explorer

I also have the same settings in transform.conf, but its not matching the results. What am i missing here? Any pointers are appreciated.

Thanks,

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...