Below is the search string I am using. Everything works like perfect except for the description field. The field remains blank when it should hold the description value. Is it because I am not using a CIDR match? I have tried a few variances of this with no luck. The csv file is populated from an hourly report. Any input is greatly appreciated.
index=my_index sourcetype=my_sourcetype local_orig=F action=allowed
[| inputcsv scanning_ip.csv]
| eval duration=round(duration,2)
| eval description=case(src="220.127.116.11/25", "This is our scanner, please ignore", src="18.104.22.168/16", "This is a government scanner, please ignore")
| table _time src src_port dest dest_port duration transport service conn_state_meaning description
| rename duration as "Duration_(seconds)"
| dedup src dest_port
| sort by src _time description