Splunk Search

Extract IP Address with rex or trim

frankagustinus
Explorer

I have this line from my Windows logs :

**** ALERT **** 10.0.0.3 gave false logon/password to POP server; user: desk1@mydomain.com 

But I want to extract "10.0.0.3" and shows how many times "10.0.0.3" or any other IP Address gave false logon in a day on a bar chart. Tried to google rex but i'm still in the dark. Can anyone help me how to extract "10.0.0.3" ?

rex "\*\*\*\* ALERT \*\*\*\* (?<IP_Add>) .... 

??? I have no idea how to do it.

Thanks,
Frank

Tags (2)
1 Solution

Ayn
Legend

This should do it:

... | rex "\*{4} ALERT \*{4} (?<IP_add>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"

View solution in original post

kristian_kolb
Ultra Champion
... | rex "\*{4} ALERT \*{4} (?<IP_add>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}).*(?<email>[\S]+)$"

should do it.

/kristian

0 Karma

kristian_kolb
Ultra Champion

updated with correct highlighting to show the backslashes. sorry. /k

0 Karma

frankagustinus
Explorer

Thanks Ayn .. It works.

I just received a new requirement. Users also wanted to retrieve the email address desk1@mydomain.com. Can you help me ? Can we extract the two fields in one rex ?

0 Karma

lguinn2
Legend

Try this (updated for new requirement to extract email address)

yoursearch |
rex "ALERT \*+\s(?<ip_add>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\s.*?user:\s(?<email>\S+)" |
chart count by ip_add email

BTW, you may find http://www.regular-expressions.info a helpful site; it's one of my favorites.

tdthorwald
Explorer

https://www.regular-expressions.info/

The link above is broken (last o is missing)

0 Karma

Ayn
Legend

This should do it:

... | rex "\*{4} ALERT \*{4} (?<IP_add>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"

tdthorwald
Explorer

What is the reason why the asterisk can be repeated with {4}, but \d{1,3}. cannot?

0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! &#x1f308; In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...