How do I add CIDR lookup tables and match them against IP addresses? Currently, we are expanding the CIDR range into the complete list of all IP addresses in the range and using that as the lookup table. However, sometimes these ranges are enormous, especially for IPv6 addresses, making them too large to enumerate.
To do this, you can create a Lookup Table containing the CIDR list. See Panther's Enrichment: Lookup Tables documentation for more information.
Here is an example schema:
validate: cidr: "any"
This schema allows you to use CIDR ranges in your Lookup Table dataset, as shown below:
ip_range | location ---------------+--------------------- 184.108.40.206/32 | SanFran Office 220.127.116.11/24 | Berlin Office 18.104.22.168/24 | Hong Kong Data Centre ...
When an IP address, such as
22.214.171.124 is received, it can be correctly enriched as