Splunk Search

Mapping IPs to netmask

FRoth
Contributor

I got a list of network masks used in our company and would like to map the ip addresses in my logs to these netmasks. All the networks are class C and the list ist in CSV format.


Format:

10.30.4.0/24,Administration I

10.30.5.0/24,Administration II

10.71.30.0/24,Production ES

10.71.31.0/24,Production FR

Is there a description on how to get this mapping done?


Do I need to extract a new field matching only the first three parts of the IP? Then adapting the CSV to contain only "xxx.xxx.xxx,description".

Would this be the best way to go?



Thanks

0 Karma

Ayn
Legend

Simply use your CSV directly as a lookup file and specify in your transforms.conf directive that Splunk should do CIDR matches on the first field. More information here: http://splunk-base.splunk.com/answers/5916/using-cidr-in-a-lookup-table

And here: http://docs.splunk.com/Documentation/Splunk/latest/Admin/Transformsconf

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...