Michael Wilde replied to Nikita's discussion Count failures and success via transaction
Nikita posted a discussionI've tried and failed to extract the IP Address field such that it only includes sets of 4 numbers that are all separated by periods. The built-in Splunk Regex pattern generator always seems to tag additional text or punctuation that makes it took specific.
For instance, the pattern generator tells me to use this:
(?i) accepted: (?P<FIELDNAME>.*)
That works to find 172.25.97.121 in the line below:
2010-03-16 09:46:57.288/[NioTCPListener, swiftlet=sys$jms, port=4001]/INFORMATION/connection accepted: 172.25.97.121
But the same Regex doesn't find the same IP address in this line:
2010-03-16 09:45:15.986/sys$jms/INFORMATION/JMSConnection v630/172.25.97.121:2355/connection closed
Any ideas?
Thanks,
Swack
Tags:
Permalink Reply by Patrick Swackhammer on March 16, 2010 at 8:22am
Permalink Reply by Ferry Leirissa on March 17, 2010 at 4:17am
Permalink Reply by Ferry Leirissa on March 17, 2010 at 6:07am
Permalink Reply by Patrick Swackhammer on March 17, 2010 at 2:14pm
Permalink Reply by Patrick Swackhammer on March 23, 2010 at 7:26am
Permalink Reply by Michael Wilde on April 6, 2010 at 2:52am
Permalink Reply by James Esposito on April 3, 2010 at 12:30pm
Permalink Reply by Siegfried Puchbauer on April 6, 2010 at 4:57am © 2012 Created by Michael Wilde.
