I have a log set from FW's. These logs have a field called "src." From what I can tell, this field is populated with values such as:
Console or telnet
I'm looking to have two fields created from the "src" field, one name IP if the value in "src" is an IP and "src_nt_host" if the value is not an ip_address. A small sample from the logged event:
From: Console or telnet.
Any help / guidance is greatly appreciated.