Network & Location Query Functions

Humio's query functions take a set of events, parameters, or configurations; and produce, reduce, or modify values within that set, or within the events themselves within the query pipeline.

Table: Network Query Functions

FunctionImplied ArgumentAvailabilityDescription
asn([as], [field])field Determines autonomous system number and organization associated.
cidr([column], [field], [file], [negate], [subnet])field Filters events using CIDR subnets.
communityId([as], destinationip, [destinationport], [icmpcode], [icmptype], proto, [seed], sourceip, [sourceport]) introduced in 1.33Computes the Community ID, a standard for hashing network flows.
rdns([as], field, [server])field Events using RDNS lookup.
shannonEntropy([as], field)field Calculates a entropy measure from a string of characters.
subnet([as], bits, field)field Computes a subnet from a IPV4 field.
urlDecode([as], field)field URL-decodes the contents of a string field.
urlEncode([as], field, [type])field URL-encodes the contents of a string field.