Splunk Search

Extract IP from TCPDUMP

DTERM
Contributor

How can I extract the source IP from the following log format?

16:13:40.860435 IP 192.54.112.34.domain > 61.220.8.179.61415: 32341- 0/5/6 (207)

All I'm interested in is the 192.54.112.34 IP address?

Thanks....

Tags (1)
0 Karma

Ayn
Legend

Umm, use the Interactive Field Extractor? I would write in more detail on creating your own regex, but seeing as I recall you asking the same kind of question before it seems you would benefit from using the IFX.

0 Karma

DTERM
Contributor

The IFX does not show the 192.54.112.34.domain or the 61.220.8.179.61415: 32341 fields. Why is that?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...