Splunk Search

Extract IP Address with rex or trim

frankagustinus
Explorer

I have this line from my Windows logs :

**** ALERT **** 10.0.0.3 gave false logon/password to POP server; user: desk1@mydomain.com 

But I want to extract "10.0.0.3" and shows how many times "10.0.0.3" or any other IP Address gave false logon in a day on a bar chart. Tried to google rex but i'm still in the dark. Can anyone help me how to extract "10.0.0.3" ?

rex "\*\*\*\* ALERT \*\*\*\* (?<IP_Add>) .... 

??? I have no idea how to do it.

Thanks,
Frank

Tags (2)
1 Solution

Ayn
Legend

This should do it:

... | rex "\*{4} ALERT \*{4} (?<IP_add>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"

View solution in original post

kristian_kolb
Ultra Champion
... | rex "\*{4} ALERT \*{4} (?<IP_add>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}).*(?<email>[\S]+)$"

should do it.

/kristian

0 Karma

kristian_kolb
Ultra Champion

updated with correct highlighting to show the backslashes. sorry. /k

0 Karma

frankagustinus
Explorer

Thanks Ayn .. It works.

I just received a new requirement. Users also wanted to retrieve the email address desk1@mydomain.com. Can you help me ? Can we extract the two fields in one rex ?

0 Karma

lguinn2
Legend

Try this (updated for new requirement to extract email address)

yoursearch |
rex "ALERT \*+\s(?<ip_add>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\s.*?user:\s(?<email>\S+)" |
chart count by ip_add email

BTW, you may find http://www.regular-expressions.info a helpful site; it's one of my favorites.

tdthorwald
Explorer

https://www.regular-expressions.info/

The link above is broken (last o is missing)

0 Karma

Ayn
Legend

This should do it:

... | rex "\*{4} ALERT \*{4} (?<IP_add>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"

tdthorwald
Explorer

What is the reason why the asterisk can be repeated with {4}, but \d{1,3}. cannot?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...