if you don't have ip filed in raw data and want use rex to take out IP address , plus want know how much data coming from that ip for a day. index=<YourIDXname>earliest=-1d@d sourcetype =<"if any"> |rex "^[^\t\n]*\t(?P<srcip>[^\t]+)" | eval size=len(_raw) | stats sum(size) as bytes by srcip | eval KB=round(bytes/1024,2) |lookup iptest.csv local=true ManagementIP as srcip OUTPUT SiteIdentifier HostName DeviceManufactorer DeviceType | search HostName=* | dedup srcip | table SiteIdentifier HostName DeviceManufactorer DeviceType srcip KB | rename srcip as "Matched IPAddress" |sort by SiteIdentifier DeviceManufactorer
... View more