Splunk Search

how to convert ip

khyoung7410
Communicator

Hi

How to convet ip ?

ex)
SRC_IP=-1234567890 ===>> SRC_IP=1.2.3.4

Tags (1)
0 Karma

JLeeatCBA
Explorer

Try this:

| eval ipsi=-1978431425| eval ip=if(ipsi<1,ipsi+2147483648,ipsi) | eval aaa=floor(ip/16777216) | eval bbb=floor((ip-aaa*16777216)/65536) | eval ccc=floor((ip-(aaa*16777216+bbb*65536))/256)| eval ddd=ip-(aaa*16777216+bbb*65536+ccc*256) | eval ipv4=tostring(aaa)+"."+tostring(bbb)+"."+tostring(ccc)+"."+tostring(ddd) | table ipsi ip ipv4 

Ayn
Legend

Fixed. Always indent code blocks with 4 spaces

0 Karma

JLeeatCBA
Explorer

For some reason, something consumed the stars meaning multiply - so bbb65536 really means multiply bbb by 65536

0 Karma

Ayn
Legend
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...