To pull in specific events in splunk i am trying to write a regex to identify lines that matches both the conditions
1: app_protocol=http or https
2. src_ip = starts with 15. or 16.
This is what i have , but doesnt seem to be working , am i doing somting wrong ?
May want to paste in a raw log for testing, but you can give this a go:
View solution in original post