<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP version agnostic regular expression in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/IP-version-agnostic-regular-expression/m-p/162528#M46091</link>
    <description>&lt;P&gt;So this will match a lot of your examples. BUT it will also match single characters from &lt;CODE&gt;[a-f]&lt;/CODE&gt;....  that needs fixed.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;NOTE:&lt;/CODE&gt; These regexes will NOT VALIDATE the IP, merely match the structure.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;((::)?[\da-f]{1,4}[:\.]{0,2}){1,8}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It may be easier to match IPv4, and then IPv6 and combine it with an &lt;CODE&gt;|&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;This matches every single item in your list, without single characters and places it into a single capture group for use.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;((?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::))
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So you could do: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex field=_raw "(?&amp;lt;src_ip&amp;gt;(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::))"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 06 Aug 2015 16:07:03 GMT</pubDate>
    <dc:creator>alacercogitatus</dc:creator>
    <dc:date>2015-08-06T16:07:03Z</dc:date>
    <item>
      <title>IP version agnostic regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IP-version-agnostic-regular-expression/m-p/162527#M46090</link>
      <description>&lt;P&gt;Just wondering if anybody's succeeded in creating an IP version agnostic regular expression?&lt;/P&gt;

&lt;P&gt;I'd like one regex to match both IPv4 and IPv6 addresses, matching against any of these tests:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;TEST: 1:2:3:4:5:6:7:8&lt;/LI&gt;
&lt;LI&gt;TEST: 1::                              1:2:3:4:5:6:7::&lt;/LI&gt;
&lt;LI&gt;TEST: 1::8             1:2:3:4:5:6::8  1:2:3:4:5:6::8&lt;/LI&gt;
&lt;LI&gt;TEST: 1::7:8           1:2:3:4:5::7:8  1:2:3:4:5::8&lt;/LI&gt;
&lt;LI&gt;TEST: 1::6:7:8         1:2:3:4::6:7:8  1:2:3:4::8&lt;/LI&gt;
&lt;LI&gt;TEST: 1::5:6:7:8       1:2:3::5:6:7:8  1:2:3::8&lt;/LI&gt;
&lt;LI&gt;TEST: 1::4:5:6:7:8     1:2::4:5:6:7:8  1:2::8&lt;/LI&gt;
&lt;LI&gt;TEST: 1::3:4:5:6:7:8   1::3:4:5:6:7:8  1::8&lt;/LI&gt;
&lt;LI&gt;TEST: ::2:3:4:5:6:7:8  ::2:3:4:5:6:7:8 ::8       ::&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;TEST: fe08::7:8%eth0      fe08::7:8%1                                      (link-local IPv6 addresses with zone index)&lt;/LI&gt;
&lt;LI&gt;TEST: ::255.255.255.255   ::ffff:255.255.255.255  ::ffff:0:255.255.255.255 (IPv4-mapped IPv6 addresses and IPv4-translated addresses)&lt;/LI&gt;
&lt;LI&gt;TEST: 2001:db8:3:4::192.0.2.33  64:ff9b::192.0.2.33                        (IPv4-Embedded IPv6 Address)&lt;/LI&gt;
&lt;LI&gt;TEST: 192.168.1.1&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;The script at &lt;A href="https://gist.github.com/syzdek/6086792"&gt;https://gist.github.com/syzdek/6086792&lt;/A&gt; does this, but it involves some extra magic to work, not just plain regex.&lt;/P&gt;

&lt;P&gt;The closest I've come is the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[ipv46]
# matches a valid IPv4 or IPv6 address (change to [[octet]] and [[ipv6]]. 
# Has a problem with 1::3 (http://stackoverflow.com/questions/53497/regular-expression-that-matches-valid-ipv6-addresses)
Stolen from: &lt;A href="https://gist.github.com/syzdek/6086792" target="test_blank"&gt;https://gist.github.com/syzdek/6086792&lt;/A&gt;
# Extracts: ip
REGEX = (?&amp;lt;ip&amp;gt;(?:2(?:5[0-5]|[0-4][0-9])|[0-1][0-9][0-9]|[0-9][0-9]?)(?:\.(?:2(?:5[0-5]|[0-4][0-9])|[0-1][0-9][0-9]|[0-9][0-9]?)){3}|([0-9a-fA-F]{1,4}:){7,7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:)|fe08:(:[0-9a-fA-F]{1,4}){2,2}%[0-9a-zA-Z]{1,}|::(ffff(:0{1,4}){0,1}:){0,1}((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])|([0-9a-fA-F]{1,4}:){1,4}:((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9]))
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However it breaks at tests like &lt;EM&gt;2001:db8:3:4::192.0.2.33&lt;/EM&gt; and &lt;EM&gt;1::8&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Splunk has a built-in transform called &lt;EM&gt;octet&lt;/EM&gt;, but no such transform for ipv6 addresses.&lt;/P&gt;

&lt;P&gt;Anyone? &lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2015 08:16:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IP-version-agnostic-regular-expression/m-p/162527#M46090</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2015-08-06T08:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: IP version agnostic regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IP-version-agnostic-regular-expression/m-p/162528#M46091</link>
      <description>&lt;P&gt;So this will match a lot of your examples. BUT it will also match single characters from &lt;CODE&gt;[a-f]&lt;/CODE&gt;....  that needs fixed.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;NOTE:&lt;/CODE&gt; These regexes will NOT VALIDATE the IP, merely match the structure.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;((::)?[\da-f]{1,4}[:\.]{0,2}){1,8}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It may be easier to match IPv4, and then IPv6 and combine it with an &lt;CODE&gt;|&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;This matches every single item in your list, without single characters and places it into a single capture group for use.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;((?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::))
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So you could do: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex field=_raw "(?&amp;lt;src_ip&amp;gt;(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::))"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 06 Aug 2015 16:07:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IP-version-agnostic-regular-expression/m-p/162528#M46091</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2015-08-06T16:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: IP version agnostic regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IP-version-agnostic-regular-expression/m-p/162529#M46092</link>
      <description>&lt;P&gt;This is pure gold! Thanks a lot. I will add this to my Cisco Networks app to make it IP version agnostic. I'll attribute you!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2015 19:37:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IP-version-agnostic-regular-expression/m-p/162529#M46092</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2015-08-10T19:37:12Z</dc:date>
    </item>
  </channel>
</rss>

