When using PCRE regex to split a field into components, I find it frustrating. I know my regex works as I've validated this in both regex101 and debuggex.
So this is extracting details from the IIS X_Forwarded_For field. The supplied log data that was parsed extracted perfectly on both platforms and even using "grep -P". But in Splunk, I only get a full extraction when the following format is observed.
If the final ip:port is missing from the event, only the first IP is captured
I've had similar experiences over the years with Splunk, so I'm wondering if my regex fu is rubbish, regex validators are wrong or splunk has a bug that's never been fixed.
If you posted the regex as text rather than an image then we could test it ourselves to better help you.
Where did you define the regex in Splunk (props.conf, transforms.conf, Add Data Wizard, etc.)?
In Splunk, the default behavior is to keep only the first match. To accept multiple matches, use the REPEAT_MATCH or MV_ADD settings.