Splunk Search

tstats search fails when attempting cidr match on IPv6 subnets

jpawloski
Path Finder

Attempting to run a tstats search that excludes a collection of IPv6 ranges from the results as follows:

| tstats summariesonly=true allow_old_summaries=true count from data model=this where this.that="foo" NOT [|inputlookup ip_subnets.csv | rename cidr as src_ip] by this.src_ip

 

Upon running the search, I'm hit with the error 'tsidxStats: WHERE clause is not an exact query'. My gut told me that ipv6 may have had something to do with it, so I reran tests with lookups where ipv6 ranges were excluded and the searches ran successfully. Matching both ipv4 and ipv6 works as expected in non-tstats searches, so I'm not sure if ipv6 cidr range matching is supported within tstats. Can anyone assist?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...