Splunk Search

How to Join IP with CIDR?

kiran331
Builder

Hi

I'm trying to Compare the IP with CIDR Lookup to get the result.In the Lookup i got the CIDR range, City, manager.

Data in lookup:

IP Country Manager
10.21.22.23/24 US abc

Search I'm using:

index=.....|table dest_ip|join type=left dest_ip[|inputlookup range.csv|rename IP as dest_ip]|table dest_ip city Manager

Tags (2)
0 Karma

sundareshr
Legend

Look at this answer. Setup match_type = CIDR(IP) in the transforms for your lookup file

https://answers.splunk.com/answers/5916/using-cidr-in-a-lookup-table.html

0 Karma

kiran331
Builder

Thanks for the response! I added this to transforms.conf.
[range]
filename = range.csv
max_matches = 1
min_matches = 1
default_match = OK
match_type = CIDR(IP)

But when i try to search, its showing errors.

search:
index=...|lookup range IP as dest_Ip OUTPUT Manager|table dest_ip Manager

0 Karma

niddhi
Explorer

I also have the same settings in transform.conf, but its not matching the results. What am i missing here? Any pointers are appreciated.

Thanks,

0 Karma
Get Updates on the Splunk Community!

Transforming Financial Data into Fraud Intelligence

Every day, banks and financial companies handle millions of transactions, logins, and customer interactions ...

How to send events & findings from AWS to Splunk using Amazon EventBridge

Amazon EventBridge is a serverless service that uses events to connect application components together, making ...

Exciting News: The AppDynamics Community Joins Splunk!

Hello Splunkers,   I’d like to introduce myself—I’m Ryan, the former AppDynamics Community Manager, and I’m ...