There is no limit to the number of entries a data enrichment file can contain. Depending on your use case, the file either needs to contain a single list of values, or in the format of lookup=enrichment. The lookup value would be the value contained in the event, such as the Source IP. The enrichment value is the value you want to add to a field in the event, such as a data center location. Your file would need to look like this
10.1.1.1=Data Center 1
10.1.1.2=Data Center 2
For IP based enrichment, CIDR notation is supported, but regular expressions are not supported unless you are using regular expression based enrichment. Regular expression based enrichment allows you to apply a regex to an event field and enrich the event with a staitc value or the returned match from the regex.
1 of 1 people found this helpful
I assume that CIDR notation is supported when the enrichment lookup type is "32 bit IP Range" and the input file format is then:
This is on 9.6MR7.