Splunk Search

How to Join IP with CIDR?

kiran331
Builder

Hi

I'm trying to Compare the IP with CIDR Lookup to get the result.In the Lookup i got the CIDR range, City, manager.

Data in lookup:

IP Country Manager
10.21.22.23/24 US abc

Search I'm using:

index=.....|table dest_ip|join type=left dest_ip[|inputlookup range.csv|rename IP as dest_ip]|table dest_ip city Manager

Tags (2)
0 Karma

sundareshr
Legend

Look at this answer. Setup match_type = CIDR(IP) in the transforms for your lookup file

https://answers.splunk.com/answers/5916/using-cidr-in-a-lookup-table.html

0 Karma

kiran331
Builder

Thanks for the response! I added this to transforms.conf.
[range]
filename = range.csv
max_matches = 1
min_matches = 1
default_match = OK
match_type = CIDR(IP)

But when i try to search, its showing errors.

search:
index=...|lookup range IP as dest_Ip OUTPUT Manager|table dest_ip Manager

0 Karma

niddhi
Explorer

I also have the same settings in transform.conf, but its not matching the results. What am i missing here? Any pointers are appreciated.

Thanks,

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...