Splunk Search

How to retrieve unique IP address from access log through splunk ?

veeru_irf
New Member

HI
I am trying to extract Unique IP address from access log to determine the user load.

My request looks like as below
- - [01/May/2014:08:59:49 -0700] POST /connect/group/home/support-query1?p_p_id=myexample_WAR_dsp&p_p_lifecycle=2&p_p_state=normal&p_p_mode=view&p_p_cacheability=cacheLevelPage&p_p_col_id=column-1&p_p_col_count=1&action=dispatch HTTP/1.0 200 126 05507 5164

Tags (2)
0 Karma
1 Solution

MuS
Legend

Hi veeru_irf,

try something like this:

your base search here | rex "^(?<myIP>(\d+\.){3}(\d+))" | table myIP

If this matches, you can set it up as automatic field extraction so it will be extracted by Splunk directly.
Also here is a nice little page where you can test regex stuff

hope this helps to get you started ...

cheers, MuS

View solution in original post

MuS
Legend

Hi veeru_irf,

try something like this:

your base search here | rex "^(?<myIP>(\d+\.){3}(\d+))" | table myIP

If this matches, you can set it up as automatic field extraction so it will be extracted by Splunk directly.
Also here is a nice little page where you can test regex stuff

hope this helps to get you started ...

cheers, MuS

veeru_irf
New Member

thnx.. It worked

0 Karma

veeru_irf
New Member

Sorry missed out initial part
205.140.227.154 - - [01/May/2014:08:59:49 -0700] POST /connect/group/home/support-query1?p_p_id=myexample_WAR_dsp&p_p_lifecycle=2&p_p_state=normal&p_p_mode=view&p_p_cacheability=cacheLevelPage&p_p_col_id=column-1&p_p_col_count=1&action=dispatch HTTP/1.0 200 126 05507 5164

0 Karma

MuS
Legend

There is no IP in this log? Does your web server log the IP's for requests at all?

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...