<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Conditional search for multiple IP ranges in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Conditional-search-for-multiple-IP-ranges/m-p/179446#M51655</link>
    <description>&lt;P&gt;Something like this should work for you.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;process="squid" httpstatus=200 | regex clientaddress="10\.([1-9]|[1-9][0-9]|1[0-9][0-9]|200)\.([8-9][0-9]|1[0-9][0-9])\.(2(3[1-9]|4[0-9]|5[0-4]))" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The regex command will match the specified regular expression for the field clientaddress and filter out non-matching events.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Aug 2014 19:22:14 GMT</pubDate>
    <dc:creator>rahulroy_splunk</dc:creator>
    <dc:date>2014-08-12T19:22:14Z</dc:date>
    <item>
      <title>Conditional search for multiple IP ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Conditional-search-for-multiple-IP-ranges/m-p/179444#M51653</link>
      <description>&lt;P&gt;Hello there!&lt;/P&gt;

&lt;P&gt;We´re trying to plan the best way to search multiple IP ranges that possibly can going through squid to Internet.&lt;/P&gt;

&lt;P&gt;Nowadays in our enviroment we have specific IP range that can´t have access to internet. Therefore we decided to monitor this IP range creating specific alert.&lt;/P&gt;

&lt;P&gt;I have researched in splunk answers and then I made the regex bellow but it didn´t work as I expected. The IP range that I want to take is 10.(1-200).(80-199).(231-254)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;process="squid" httpstatus=200 | rex field=clientaddress "10.(?\d+).(?\d+).(?\d+)" | search (secoctect &amp;lt;200) N (79 &amp;gt; thiroctect &amp;lt;200) AND (four_octect &amp;gt;230)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Does anybody know what should I do? Any help I will appreciate it.&lt;/P&gt;

&lt;P&gt;Thanks &lt;/P&gt;</description>
      <pubDate>Tue, 12 Aug 2014 18:45:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Conditional-search-for-multiple-IP-ranges/m-p/179444#M51653</guid>
      <dc:creator>vmorita</dc:creator>
      <dc:date>2014-08-12T18:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Conditional search for multiple IP ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Conditional-search-for-multiple-IP-ranges/m-p/179445#M51654</link>
      <description>&lt;P&gt;Try like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;process="squid" httpstatus=200 | rex field=clientaddress "10\.(?&amp;lt;secoctect&amp;gt;\d+)\.(?&amp;lt;thiroctect&amp;gt;\d+)\.(?&amp;lt;four_octect&amp;gt;\d+)" | search (secoctect &amp;lt;200) AND (79 &amp;gt; thiroctect &amp;lt;200) AND (four_octect &amp;gt;230)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 12 Aug 2014 19:03:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Conditional-search-for-multiple-IP-ranges/m-p/179445#M51654</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-12T19:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Conditional search for multiple IP ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Conditional-search-for-multiple-IP-ranges/m-p/179446#M51655</link>
      <description>&lt;P&gt;Something like this should work for you.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;process="squid" httpstatus=200 | regex clientaddress="10\.([1-9]|[1-9][0-9]|1[0-9][0-9]|200)\.([8-9][0-9]|1[0-9][0-9])\.(2(3[1-9]|4[0-9]|5[0-4]))" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The regex command will match the specified regular expression for the field clientaddress and filter out non-matching events.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Aug 2014 19:22:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Conditional-search-for-multiple-IP-ranges/m-p/179446#M51655</guid>
      <dc:creator>rahulroy_splunk</dc:creator>
      <dc:date>2014-08-12T19:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: Conditional search for multiple IP ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Conditional-search-for-multiple-IP-ranges/m-p/179447#M51656</link>
      <description>&lt;P&gt;I tried like this&lt;/P&gt;

&lt;P&gt;process="squid" httpstatus=200 | rex field=clientaddress "10.(?&lt;SEC_OCTECT&gt;d+).(?&lt;THIR_OCTECT&gt;d+).(?&lt;FOUR_OCTECT&gt;d+)" | search (sec_octect&amp;lt;200) AND (thir_octect &amp;gt; 79 AND thir_octect &amp;lt; 200) AND (four_octect &amp;gt;230)&lt;/FOUR_OCTECT&gt;&lt;/THIR_OCTECT&gt;&lt;/SEC_OCTECT&gt;&lt;/P&gt;

&lt;P&gt;But it did not work yet.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:19:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Conditional-search-for-multiple-IP-ranges/m-p/179447#M51656</guid>
      <dc:creator>vmorita</dc:creator>
      <dc:date>2020-09-28T17:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: Conditional search for multiple IP ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Conditional-search-for-multiple-IP-ranges/m-p/179448#M51657</link>
      <description>&lt;P&gt;My bad, missed backslashes with d. Try the updated answer...&lt;/P&gt;</description>
      <pubDate>Tue, 12 Aug 2014 19:33:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Conditional-search-for-multiple-IP-ranges/m-p/179448#M51657</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-12T19:33:07Z</dc:date>
    </item>
  </channel>
</rss>

