Hi Team,
I will be getting below text randomly in logs, I need a regex for the 1st IP's separately & 2nd IP's separately . can someone please help to get it.
The user Risen Paur (risen.paur@mail.eeir) performed an impossible travel activity. The user was active from 117.202.23.200 in India and 173.205.24.222 in United States within 802 minutes.
@gcusello - Looking forward your help.
Assuming parts of the text are static
| rex "The user was active from (?<firstip>[\d\.]+) .+ and (?<secondip>[\d\.]+) "
HI @SabariRajanT,
the anser of @ITWhisperer is probably the correct one, to be sure, could you share some sample of your logs?
Ciao.
Giuseppe
Assuming parts of the text are static
| rex "The user was active from (?<firstip>[\d\.]+) .+ and (?<secondip>[\d\.]+) "