Splunk Search

How to extract first ip from "http_x_forwarded_for="222.xx.xx.xx, 122.211.xx.xx" using rex in Splunk search?

minhquannguyen7
Engager

here is field "http_x_forwarded_for="222.xx.xx.xx, 122.211.xx.xx"

i have try:

| rex field=_raw "http_x_forwarded_for\s*=\s*(?<ip_address>[^,\s]+)"

| table ip_address

But it not works, pls help !

Labels (2)
0 Karma

santoshneelam
Explorer

|rex "(?im)\w+\=\"(?P<http_x_forwarded_for>.[^\,]+)"

or else
|rex "(?im)\w+\=\"(?P<http_x_forwarded_for>\d+\.\d+\.\d+\.\d+)"

minhquannguyen7
Engager

thanks you @santoshneelam !  i want extract in the different log with any field look like this , what shoud i do ???

 

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...