The dojo of Splunk. Learn, share, teach, mentor.
I've tried and failed to extract the IP Address field such that it only includes sets of 4 numbers that are all separated by periods. The built-in Splunk Regex pattern generator always seems to tag additional text or punctuation that makes it took specific.
For instance, the pattern generator tells me to use this:
(?i) accepted: (?P<FIELDNAME>.*)
That works to find 172.25.97.121 in the line below:
2010-03-16 09:46:57.288/[NioTCPListener, swiftlet=sys$jms, port=4001]/INFORMATION/connection accepted: 172.25.97.121
But the same Regex doesn't find the same IP address in this line:
2010-03-16 09:45:15.986/sys$jms/INFORMATION/JMSConnection v630/172.25.97.121:2355/connection closed
Any ideas?
Thanks,
Swack
Tags:
Loading feed
Loading feed
© 2010 Created by Michael Wilde.
Powered by
.