here is field "http_x_forwarded_for="222.xx.xx.xx, 122.211.xx.xx"
i have try:
| rex field=_raw "http_x_forwarded_for\s*=\s*(?<ip_address>[^,\s]+)"
| table ip_address
But it not works, pls help !
|rex "(?im)\w+\=\"(?P<http_x_forwarded_for>.[^\,]+)"
or else
|rex "(?im)\w+\=\"(?P<http_x_forwarded_for>\d+\.\d+\.\d+\.\d+)"
thanks you @santoshneelam ! i want extract in the different log with any field look like this , what shoud i do ???