Splunk Search

Using mvappend within a cidrmatch macro

CarbonCriterium
Path Finder

I already have the following macro  `subnet(3)`  defined as the following:

 

 

| eval subnet = case(cidrmatch("$ip1$/24",src_ip), "$output_name$", cidrmatch("$ip2$",src_ip), "$output_name$")

 

 

 

If I call the macro multiple in the same search the value of the field it creates (also called subnet) will be overwritten by the latest values.   I would like to edit the macro so that calling it multiple times appends a new value to subnet.  How could I use mvappend, or another command, to accomplish this?

Labels (1)
0 Karma
1 Solution

CarbonCriterium
Path Finder

Never mind.  Figuring it out just required taking a step back and reading the docs again.

 

| eval subnet = mvappend(case(cidrmatch("$ip1$/24",src_ip), "$output_name$", cidrmatch("$ip2$",src_ip), "$output_name$"),subnet)

 

 

View solution in original post

0 Karma

CarbonCriterium
Path Finder

Never mind.  Figuring it out just required taking a step back and reading the docs again.

 

| eval subnet = mvappend(case(cidrmatch("$ip1$/24",src_ip), "$output_name$", cidrmatch("$ip2$",src_ip), "$output_name$"),subnet)

 

 

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!