Splunk Search
Highlighted

Trying to us wildcards and CIDR in a lookup table but I am having no luck

Path Finder

Ladies and Gentlemen,
I am have been trying for the better part of a week to get my lookup tables with CIDR and wildcards to work but I am having zero success.

My PROPS.CONF for both search is:
CIDR
[sourcetype]
LOOKUP_needip = CIDR neededip AS IP

wildcardIP
[sourcetype]
LOOKUP-wildcardip = Mass
IP wildcardip OUTPUT wildcard_site

TRANSFORMS.CONF:

[CIDR]
filename = CIDR.csv
match_type = CIDR(neededip)

wildcardIP

[wildcardIP]
filename = wildcard
IP.csv
DELIMS = " "
match_type = WILDCARD(wildcardip)

I am using a simple lookup at the beginning of the search ie:

sourcetype=foo host=bar [| inputlookup wildcard_IP.csv]

Are my props and transforms correct? I am at a loss.

Thanks for any help,
Ernie

0 Karma
Highlighted

Re: Trying to us wildcards and CIDR in a lookup table but I am having no luck

SplunkTrust
SplunkTrust

Check out this search result for troubleshooting:

sourcetype=foo host=bar | top wildcard_site

If that populates with sites from your lookup then your lookup works. If it does, replace your original search with this:

sourcetype=foo host=bar wildcard_site=*

The subsearch-based one you had would return a list of CIDR IPs and sites to filter for, without honouring the CIDR matching and without only looking for IPs and returning sites.

View solution in original post

0 Karma
Highlighted

Re: Trying to us wildcards and CIDR in a lookup table but I am having no luck

Path Finder

Unfortunatly, nothing is populating in the search.

0 Karma
Highlighted

Re: Trying to us wildcards and CIDR in a lookup table but I am having no luck

SplunkTrust
SplunkTrust

That suggests your automatic lookup is broken. Do post some sample events along with some sample lines from your lookup file.

What is the DELIMS setting for your lookup file supposed to do?

Highlighted

Re: Trying to us wildcards and CIDR in a lookup table but I am having no luck

Path Finder

the lookup table is set up like this:

wildcardip,"wildcard_site"
123...*,"Department of Fashion"

So I am using the DELIMS for the wildcard_site side

0 Karma
Highlighted

Re: Trying to us wildcards and CIDR in a lookup table but I am having no luck

Path Finder

I removed the DELIM, shortened the wildcard values for each IP and changed the PROPS.CONF to

LOOKUPwildcardip = wildcardIP wildcardip as dst OUTPUT wildcard_site
And I am getting results now.

Thanks for the help

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.