Splunk Search

Extract IP address from event log

seba333
Engager

Hi!

Need help with this please.

I have to extract the IP address from this:

src=45.141.87.33:53402:X19

value 53402 and value X19 could be anything.

 

help please!

 

Labels (1)

inventsekar
SplunkTrust
SplunkTrust

EDIT- verified, working good.


assuming you want to extract "45.141.87.33"

 

 

| makeresults 
| eval log = "test src=45.141.87.33:53402:X19 test" 
| rex field=log "(?<ipAddr>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})" | table ipAddr log

 

rex-ip-new.png

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...