@bwniranjan if your intent is to mask ip address prior to indexing you can refer to the following documentation: http://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata
If your intent is to mask IP address at search time you can use rex command with sed
Please confirm which one of the above two you need in case you need further details for either one!
Ask is user who is searching the event in Splunk dashboard should not see the IP address.