Hi, So basically I have tested this in 3 different Splunk SHs. One with 7.3.9 where all is working fine, another with 8.0.4.1 with same configurations (csv and lookup definition) , and another with 8.0.8, that I have upgraded to 8.1.3, also with same configuration. I have tried before matching directly with IP and it works, but not with cidr field. There's no extra whitespaces, the same lookup works properly on 7.3.9 matching cidr field. I have configured the lookup fresh via gui on both Splunk 8.X SHs and it didn't work anyway. Tried in search time use the cidrmatch function and it works. So basically the only thing not working is CIDR in lookup definition. Hope this clarifies. Thanks
... View more