- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
joock3r
Explorer
02-14-2023
07:47 AM
Hi,
I have a lookup definition that look like that:
When I'm running this search with looking up in this lookup difinition, I'm getting the wider subnet.
index="FW" action=allowed src_ip=10.0.0.1 sourcetype=fw
| lookup ipam subnet AS src_ip OUTPUT subnet AS "Source Subnet"
| table src_ip "Source Subnet" dest_ip Service Protocol app Rule Device _time
| sort 0 -_time
The ipam lookup contains amount of subnets that contatining each other (for example 10.0.0.0/16, 10.0.0.0/24).
The results that I'm getting is for the wider subnet, in my example - 10.0.0.0/16.
Is there a way to choose the smaller subnet that contains the src_ip?
Thanks 🙂
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
02-14-2023
08:54 AM
Lookup always return the first match. Edit the lookup to put the smaller subnets before the larger ones.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
02-14-2023
08:54 AM
Lookup always return the first match. Edit the lookup to put the smaller subnets before the larger ones.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
