Apologies in advance as im new to Splunk Im trying to put a name to each line below. Each src to dst is a business client. So 1st line would be cisco. 2nd would be juniper, third would be Microsoft. Once i put this in a visualtion i want to show client name rather than src or whatever. OR (src=192.168.1.1 dest=172.16.1.1) OR (src=192.168.1.2 dest=172.16.2.1) OR (src=192.168.1.3 dest=172.16.3.1) made up syntax: Name:Cisco = (src=192.168.1.1 dest=172.16.1.1) I hope you understand what im getting at - Thanks Simon
... View more