Splunk Search

How do i search for IPv6 addresses from my src_ip field.

Path Finder

I'm trying to do a search that finds IPv6 addresses. Currently our field src_ip has both IPv4 and IPv6 in it. How can i search so only events with IPv6 addresses are returned?

Tags (2)
1 Solution

Path Finder

This is a bit quick and dirty but...

sourcetype=yoursourcetype srcip=":"

View solution in original post

0 Karma

Engager

This is the simplest way i could come up with.

| regex src_ip!="(^[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}$)"

This will remove all IPv4 addresses from your search. don't forget to switch "srcip" to what field you are searching. (e,g, destip, rxhosts, txhosts)

0 Karma

Engager

this is the most simplest way i came up with.

| regex src_ip!="(^[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}$)"

this will remove all IPv4 addresses from your search.

0 Karma

Path Finder

This is a bit quick and dirty but...

sourcetype=yoursourcetype srcip=":"

View solution in original post

0 Karma

Path Finder

I feel as though I should slap myself in the face for not figuring this out on my own! just tried it and it worked. did this src_ip=":"

0 Karma