Splunk Search

Predefined Group

balcv
Contributor

What is the best way to define a "group" of ip subnets called server_subnet then use that in searches.

I have about 19 subnets used to host our server fleet and I would like to define these subnets and assign a name such as server_subnets so I can then write a search that references that name. For example

index="*" src_ip="server_subnets" | stats count by host

OR

index="*" dest_ip!="server_subnets"

Thanks

0 Karma
1 Solution

renjith_nair
SplunkTrust
SplunkTrust

@balcv ,

You may use tags or eventtypes to group fields/values

Most of the options are detailed in the Classify and group similar events

View solution in original post

renjith_nair
SplunkTrust
SplunkTrust

@balcv ,

You may use tags or eventtypes to group fields/values

Most of the options are detailed in the Classify and group similar events

View solution in original post

.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!