<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extract IP from TCPDUMP in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extract-IP-from-TCPDUMP/m-p/86521#M22062</link>
    <description>&lt;P&gt;The IFX does not show the 192.54.112.34.domain or the 61.220.8.179.61415: 32341 fields.  Why is that?&lt;/P&gt;</description>
    <pubDate>Thu, 11 Oct 2012 19:42:37 GMT</pubDate>
    <dc:creator>DTERM</dc:creator>
    <dc:date>2012-10-11T19:42:37Z</dc:date>
    <item>
      <title>Extract IP from TCPDUMP</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-IP-from-TCPDUMP/m-p/86519#M22060</link>
      <description>&lt;P&gt;How can I extract the source IP from the following log format?&lt;/P&gt;

&lt;P&gt;16:13:40.860435 IP 192.54.112.34.domain &amp;gt; 61.220.8.179.61415: 32341- 0/5/6 (207)&lt;/P&gt;

&lt;P&gt;All I'm interested in is the 192.54.112.34 IP address?&lt;/P&gt;

&lt;P&gt;Thanks....&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2012 20:48:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-IP-from-TCPDUMP/m-p/86519#M22060</guid>
      <dc:creator>DTERM</dc:creator>
      <dc:date>2012-10-10T20:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: Extract IP from TCPDUMP</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-IP-from-TCPDUMP/m-p/86520#M22061</link>
      <description>&lt;P&gt;Umm, use the Interactive Field Extractor? I would write in more detail on creating your own regex, but seeing as I recall you asking the same kind of question before it seems you would benefit from using the IFX.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2012 21:10:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-IP-from-TCPDUMP/m-p/86520#M22061</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-10-10T21:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: Extract IP from TCPDUMP</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-IP-from-TCPDUMP/m-p/86521#M22062</link>
      <description>&lt;P&gt;The IFX does not show the 192.54.112.34.domain or the 61.220.8.179.61415: 32341 fields.  Why is that?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2012 19:42:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-IP-from-TCPDUMP/m-p/86521#M22062</guid>
      <dc:creator>DTERM</dc:creator>
      <dc:date>2012-10-11T19:42:37Z</dc:date>
    </item>
  </channel>
</rss>

