Forget the rest of search. What do you get from the following? index="logs" sourceip="x.x.x.x" OR destip="x.x.x.x"
| lookup file.csv cidr AS sourceip OUTPUT provider AS sourceprovider, area AS s...
See more...
Forget the rest of search. What do you get from the following? index="logs" sourceip="x.x.x.x" OR destip="x.x.x.x"
| lookup file.csv cidr AS sourceip OUTPUT provider AS sourceprovider, area AS sourcearea, zone AS sourcezone , region AS sourceregion, cidr AS src_cidr
| lookup file.csv cidr AS destip OUTPUT provider AS destprovider, area AS destarea, zone AS destzone, region AS destregion, cidr AS dest_cidr
| table sourceip sourceprovider sourcearea sourcezone sourceregion src_cidr
destip destprovider destarea destzone destregion dest_cidr Is the output correct? Using your mock lookup data, I made the following emulation | makeresults format=csv data="sourceip, destip
1.1.1.116,10.5.5.5
10.0.0.5,2.2.2.3
2.2.2.8, 1.1.1.90
192.168.8.1,10.6.0.10"
``` the above emulates
index="logs" sourceip="x.x.x.x" OR destip="x.x.x.x"
```
| lookup file.csv cidr AS sourceip OUTPUT provider AS sourceprovider, area AS sourcearea, zone AS sourcezone , region AS sourceregion, cidr AS src_cidr
| lookup file.csv cidr AS destip OUTPUT provider AS destprovider, area AS destarea, zone AS destzone, region AS destregion, cidr AS dest_cidr
| fields sourceip sourceprovider sourcearea sourcezone sourceregion src_cidr
destip destprovider destarea destzone destregion dest_cidr This is what I get, exactly as expected sourceip sourceprovider sourcearea sourcezone sourceregion src_cidr destip destprovider destarea destzone destregion dest_cidr 1.1.1.116 Unit 1 Finance 2 1.1.1.1/24 10.5.5.5 10.0.0.5 2.2.2.3 Unit 2 HR 16 2.2.2.2/27 2.2.2.8 Unit 2 HR 16 2.2.2.2/27 1.1.1.90 Unit 1 Finance 2 1.1.1.1/24 192.168.8.1 10.6.0.10