I am trying to extract Ips from the field called Text, where this field contains Ips & some string values , this field not contains only one IP all time, it may contain 2 Ips , 3 or 5 or more than that. Ips will not be same for all the events and the string "value" is same for all the events
eg.,
Text= value 127.0.0.1,10.x.x.x, 10.x.x.1,10.x.x.3
Text= value 145.X.X.2, 19.x.x.3
Text= value 123.X.X.X
So, i need to extract only ip separetely(irrespective of count of Ips) and "value" in one field.
Try
|rex field=Text max_match=0 "(?<ip_address>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"
Try
|rex field=Text max_match=0 "(?<ip_address>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"