Getting Data In

Why is field is not extracted properly for Windows event log?

Nraj87
Loves-to-Learn Everything

Field is not extracted properly for Windows event log  where Ip address mark as "Client IP"

Try to extract Field below Regexs but no luck, in _internal logs Regexs was applied to the prorp.conf Successfully.

Please Suggest if anyone face this issue.

Regex 1

(?<ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})

Regex 2
[^+]Client\s+IP\:\s+(?<ip>\d+.\d+.\d+.\d+)\s+

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nraj87,

could you share a ample of your logs highlighting the string to associate to IP?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...