Splunk Search

search cidr without using "src_ip OR dest_ip"?

jpreis
New Member

Is there a way to search a cidr notation without using "src_ip OR dest_ip"?
I have a bunch of ips i want to search for and would like to search for a bunch of them at once.

Tags (2)
0 Karma

mydog8it
Builder

If you don't use a field name the search command will interpret the CIDR as a string, it will not make a match. You must use a field name in the search, like src_ip or dest_ip.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...