Splunk Search

tstats search fails when attempting cidr match on IPv6 subnets

jpawloski
Path Finder

Attempting to run a tstats search that excludes a collection of IPv6 ranges from the results as follows:

| tstats summariesonly=true allow_old_summaries=true count from data model=this where this.that="foo" NOT [|inputlookup ip_subnets.csv | rename cidr as src_ip] by this.src_ip

 

Upon running the search, I'm hit with the error 'tsidxStats: WHERE clause is not an exact query'. My gut told me that ipv6 may have had something to do with it, so I reran tests with lookups where ipv6 ranges were excluded and the searches ran successfully. Matching both ipv4 and ipv6 works as expected in non-tstats searches, so I'm not sure if ipv6 cidr range matching is supported within tstats. Can anyone assist?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...