Splunk Search

Lookup with IP range

MoermansM
New Member

Hi there, what's the best way to append a search with a lookup with ip subnet ranges and some extra information for those IP's?

iprange.csv

 clientip, zone, areacode
127.0.0.1/24, home, 255

I've added the transforms.conf in the app:

[iprange]
filename = iprange.csv
default_match = OK
match_type = CIDR(clientip)

and the search:

 sourcetype=firewall area=* | lookup iprange.csv clientip as src OUTPUT clientip zone area |table src, zone, area

Yet it doesn't seem to work so far, any suggestions?

0 Karma

niddhi
Explorer

I have exactly the same scenario and its not working. I don't want to add the ip's manually as src, that will defeat the purpose of having a dynamic lookup. Any pointers are appreciated.

0 Karma

anjambha
Communicator

Hi MoermansM,

You are not getting output because the ip you are getting from firewall is without subnet and your csv contain ip with subnet so can not map the column.

So in this case the alternative solution for this is to add one more column to your iprange.csv as below: if you are doing this modification then there is no need of transforms.conf.

src, clientip, zone, areacode
127.0.0.1, 127.0.0.1/24, home, 255

then try this ..

sourcetype=firewall area=* | dedup src | lookup iprange.csv src OUTPUT src clientip zone area |table src, clientip, zone, area
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...