<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP address for the last occurrence in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566246#M197346</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp; Thanks for the reply!&lt;/P&gt;&lt;P&gt;rex ".*(?&amp;lt;IP&amp;gt;\d+\.\d+\.\d+\.\d+)"&amp;nbsp; - this is capturing the last IP, but&amp;nbsp; instead of capturing "230.44.333.122" , its capturing&amp;nbsp;"0.44.333.222"&lt;/P&gt;&lt;P&gt;Appreciate your help on this.&lt;/P&gt;</description>
    <pubDate>Wed, 08 Sep 2021 05:58:49 GMT</pubDate>
    <dc:creator>VS0909</dc:creator>
    <dc:date>2021-09-08T05:58:49Z</dc:date>
    <item>
      <title>IP address for the last occurrence</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566111#M197274</link>
      <description>&lt;P&gt;Can someone please help with the Splunk query for the below scenario:&lt;/P&gt;&lt;P&gt;I want to extract last IP address by a regular expression (regex) , for an event which has one or more IP addresses.&lt;/P&gt;&lt;P&gt;If the event has one IP ---&amp;gt; then extract that IP&lt;/P&gt;&lt;P&gt;If the event has more than one IP ---&amp;gt; then extract the last IP&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 10:42:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566111#M197274</guid>
      <dc:creator>VS0909</dc:creator>
      <dc:date>2021-09-07T10:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: IP address for the last occurrence</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566112#M197275</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp; Can you help with the Splunk query for the below scenario:&lt;/P&gt;&lt;P&gt;I want to extract last IP address by a regular expression (regex) , for an event which has one or more IP addresses.&lt;/P&gt;&lt;P&gt;If the event has one IP ---&amp;gt; then extract that IP&lt;/P&gt;&lt;P&gt;If the event has more than one IP ---&amp;gt; then extract the last IP&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 10:43:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566112#M197275</guid>
      <dc:creator>VS0909</dc:creator>
      <dc:date>2021-09-07T10:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: IP address for the last occurrence</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566114#M197276</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225618"&gt;@VS0909&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Could you share any sample of your logs?&lt;/P&gt;&lt;P&gt;possibly some event with one IP and someone else with many IPs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 11:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566114#M197276</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-09-07T11:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: IP address for the last occurrence</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566120#M197278</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp; Please find below details&lt;/P&gt;&lt;P&gt;There may be one or more IP's in the event&lt;/P&gt;&lt;P&gt;Sample logs with two IP's:&lt;/P&gt;&lt;P&gt;- - - [07/Sep/2020:06:42:58 -0500] "ssa/edit.jsp?assetURI HTTP/1.1" HTTP/1.1 200 1111 1111 0.222/444 Mozilla/1.0 (Windows NT 1.0; Win64; x64)110.10.222.22 LKMKOIL8098mnmdsLO799 &lt;STRONG&gt;230.44.333.122&lt;/STRONG&gt; wwwsss.abc.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sample logs with one IP:&lt;/P&gt;&lt;P&gt;- - - [07/Sep/2020:06:42:58 -0500] "ssa/edit.jsp?assetURI HTTP/1.1" HTTP/1.1 200 1111 1111 0.222/444 Mozilla/1.0 (Windows NT 1.0; Win64; x64) - &lt;A href="http://abc:8080/bbb/aaa/mmm?_requestid=39999" target="_blank"&gt;http://abc:8080/bbb/aaa/mmm?_requestid=39999&lt;/A&gt; &lt;STRONG&gt;230.44.333.222&lt;/STRONG&gt; LKMKOIL8098mnmdsLO799 - abcde1&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 11:54:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566120#M197278</guid>
      <dc:creator>VS0909</dc:creator>
      <dc:date>2021-09-07T11:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: IP address for the last occurrence</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566123#M197281</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225618"&gt;@VS0909&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "\s(?&amp;lt;IP&amp;gt;\d+\.\d+\.\d+\.\d+)"&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/UxpUvx/1" target="_blank"&gt;https://regex101.com/r/UxpUvx/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 12:03:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566123#M197281</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-09-07T12:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: IP address for the last occurrence</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566136#M197288</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp; Thanks for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;| rex "\s(?&amp;lt;IP&amp;gt;\d+\.\d+\.\d+\.\d+)"&lt;/P&gt;&lt;P&gt;This regex is capturing all the IPs in the event. I just need the last IP . can you please help with that.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 13:06:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566136#M197288</guid>
      <dc:creator>VS0909</dc:creator>
      <dc:date>2021-09-07T13:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: IP address for the last occurrence</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566140#M197290</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225618"&gt;@VS0909&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(?&amp;lt;IP&amp;gt;\d+\.\d+\.\d+\.\d+)"
| eval IP=mvindex(IP,-1)&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 13:36:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566140#M197290</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-09-07T13:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: IP address for the last occurrence</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566145#M197292</link>
      <description>&lt;P&gt;Thanks for the repply&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;. It is still taking the first value. Can you please help! Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 13:53:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566145#M197292</guid>
      <dc:creator>VS0909</dc:creator>
      <dc:date>2021-09-07T13:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: IP address for the last occurrence</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566155#M197298</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225618"&gt;@VS0909&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex ".*(?&amp;lt;IP&amp;gt;\d+\.\d+\.\d+\.\d+)"&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/UxpUvx/2" target="_blank"&gt;https://regex101.com/r/UxpUvx/2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 14:37:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566155#M197298</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-09-07T14:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: IP address for the last occurrence</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566186#M197312</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225618"&gt;@VS0909&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Please try below (using negative lookahead);&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(?!.+\s\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})(?&amp;lt;ip&amp;gt;\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 07 Sep 2021 16:03:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566186#M197312</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-09-07T16:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: IP address for the last occurrence</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566246#M197346</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp; Thanks for the reply!&lt;/P&gt;&lt;P&gt;rex ".*(?&amp;lt;IP&amp;gt;\d+\.\d+\.\d+\.\d+)"&amp;nbsp; - this is capturing the last IP, but&amp;nbsp; instead of capturing "230.44.333.122" , its capturing&amp;nbsp;"0.44.333.222"&lt;/P&gt;&lt;P&gt;Appreciate your help on this.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 05:58:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IP-address-for-the-last-occurrence/m-p/566246#M197346</guid>
      <dc:creator>VS0909</dc:creator>
      <dc:date>2021-09-08T05:58:49Z</dc:date>
    </item>
  </channel>
</rss>

