Splunk Search

Extract IP address from event log

seba333
Engager

Hi!

Need help with this please.

I have to extract the IP address from this:

src=45.141.87.33:53402:X19

value 53402 and value X19 could be anything.

 

help please!

 

Labels (1)

inventsekar
SplunkTrust
SplunkTrust

EDIT- verified, working good.


assuming you want to extract "45.141.87.33"

 

 

| makeresults 
| eval log = "test src=45.141.87.33:53402:X19 test" 
| rex field=log "(?<ipAddr>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})" | table ipAddr log

 

rex-ip-new.png

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...