I have a dozen /24 subnets that I am looking to find any IP addresses on that subnet in my search as well as a addresses from several /25 and /26 subnets. Thanks, in advance.
Standard searches and tstats ... where both support native CIDR equalities (but NOT inequalities) and where has cidrmatch() function.
tstats ... where
I believe you may make more hay by using a where clause and a cidrmatch function: https://docs.splunk.com/Documentation/Splunk/7.3.2/SearchReference/ConditionalFunctions#cidrmatch.28...
Example: | where cidrmatch("184.108.40.206/25", ip)
| where cidrmatch("220.127.116.11/25", ip)