Splunk Search

tstats search fails when attempting cidr match on IPv6 subnets

jpawloski
Path Finder

Attempting to run a tstats search that excludes a collection of IPv6 ranges from the results as follows:

| tstats summariesonly=true allow_old_summaries=true count from data model=this where this.that="foo" NOT [|inputlookup ip_subnets.csv | rename cidr as src_ip] by this.src_ip

 

Upon running the search, I'm hit with the error 'tsidxStats: WHERE clause is not an exact query'. My gut told me that ipv6 may have had something to do with it, so I reran tests with lookups where ipv6 ranges were excluded and the searches ran successfully. Matching both ipv4 and ipv6 works as expected in non-tstats searches, so I'm not sure if ipv6 cidr range matching is supported within tstats. Can anyone assist?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...