Hi guys,
I am building a search where I want to report on location based on source IP address. For example within our internal network the subnet 10.0.0.0/24 corresponds to Brewton, whereas 10.1.133.0/23 also corresponds to Brewton. (I have about 23 subnets for this one location)
I have tried using this:
my search | eval subnet=case(cidrmatch("10.0.0.0/24",src)
However, it is not working at all. It will be great if you guys can give me some suggestions.
Thank you!
Here is a previous answer that should help.
http://splunk-base.splunk.com/answers/54880/group-ip-addresses-in-cidr-format
What would be the desired result and what's the current result? Your eval statement is incomplete, so it's hard to tell from that.