Splunk Search

Splunk Lookup overide

sumitkathpal
Explorer

Hi Team,

we have lookup file which is doing enrichment however we have define the lookup using CIDR values of ip address and working well.
below is lookup file working well
ip mac nt_host dns owner priority lat long city country bunit category
10.228.80.0/24 is category as workstation

now we have ip 10.228.80.50 which we need to categorized as laptop , how we can do that , right now everything is coming as workstation

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you tried adding "10.228.80.50 laptop" to the lookup file before the "10.228.80.0/24" entry? The first match in the file should prevail.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...