Hello
i want to extract ip field from a log but i give error.
this is a part of my log: ",\"SourceIp\":\"10.10.6.0\",\"N
i want 10.10.6.0 as a field.
can you help me?
This looks awfully close to a part of a json structure inserted as a string field in another json structure.
It is bad on at least two levels.
1) Embedding json as escaped string prevents it from being properly parsed by Splunk
2) Extracting from structured data with regexes is asking for trouble
What have you tried so far? What error do you get? Are you trying to extract the field at index-time or search-time?
Have you tried this rex command in your search?
| rex "SourceIp\\\\\\":\\\\\\"(?<SourceIp>[\d\.]+)"